Nicole Perlroth Keynote: The New Frontline: Cyber on the Precipice
Black Hat USA 2025 · Day 1 · Briefings
Overview
Nicole Perlroth, the former New York Times cybersecurity correspondent and author of This Is How They Tell Me the World Ends, delivered a sweeping keynote tracing cybersecurity's escalating threat landscape — from Stuxnet to Volt Typhoon to AI-accelerated attacks. Her central argument: the industry has consistently treated catastrophic incidents as edge cases, and that pattern of denial is now a national security liability. The only way forward, she says, is courage — from individual practitioners, from institutions, and from the public-private partnerships that have already proven they can work. ---

Key moments
- 6:00 China's Volt Typhoon pre-positioned in US critical infrastructure for years undetected
- 11:59 NYT was hacked by Chinese APT Unit 61398 during Perlroth's first year
- 17:59 Salt Typhoon compromised all major US telecoms including wiretap systems
- 26:00 DOGE slashing CISA and cyber workforce creates intelligence vacuum at critical moment
- 33:59 NSA's offensive cyber capabilities now risk attribution as US policy shifts
- 42:00 Warning: adversaries now have 10+ years of US 0-day playbooks from leaks
- 47:59 Ransomware funding North Korean nuclear program via crypto theft at scale
- 52:00 Thesis: cyber community must fill governance vacuum left by retreating US government
The New Frontline: Cyber on the Precipice
Speaker: Nicole Perlroth — Author, Journalist, Venture Partner at Ballistic Ventures; Former Cybersecurity Correspondent, The New York Times
Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas
YouTube: https://www.youtube.com/watch?v=4C1UL5sO_ME
Reading time: 7 min
Type: Keynote
TL;DR
Nicole Perlroth, the former New York Times cybersecurity correspondent and author of This Is How They Tell Me the World Ends, delivered a sweeping keynote tracing cybersecurity's escalating threat landscape — from Stuxnet to Volt Typhoon to AI-accelerated attacks. Her central argument: the industry has consistently treated catastrophic incidents as edge cases, and that pattern of denial is now a national security liability. The only way forward, she says, is courage — from individual practitioners, from institutions, and from the public-private partnerships that have already proven they can work.
Introduction
When Nicole Perlroth joined The New York Times as its cybersecurity correspondent in 2011, she walked in "right after Stuxnet" and walked out "right after SolarWinds." Over a decade covering the beat, she had a front-row seat to a transformation that most of the public — and many policymakers — still haven't fully absorbed: cyber threats are no longer anomalies. They are the new normal, picking up in frequency and severity with each iteration.
At Black Hat USA 2025, Perlroth used her keynote to connect the dots between a decade of landmark incidents, the Chinese pre-positioning campaign underway inside U.S. critical infrastructure, and the approaching inflection point of AI. Her message was equal parts diagnosis and call to arms: the security community has the courage to meet this moment, but it needs to stop waiting for permission.
A Decade of Firsts That We Treated as Anomalies
▶ Watch: The Decade of Firsts (14:00)
Perlroth framed her decade at the Times as a "decade of firsts" — the first major corporate acknowledgment of a Chinese nation-state hack (Google and Operation Aurora), the first attack through a trusted software update, the first major infrastructure breach via an HVAC system. Each of these moments made the front page, generated discussion for a few weeks, and then faded. The industry moved on. The attack surface expanded.
What she wishes she had seen more clearly in the moment was the through line: each incident was "a slight twist, a slight advancement, a slight innovation on the high-profile attack that had come before it." Stuxnet led to Shamoon. Shamoon's wiper technique resurfaced in NotPetya. Sony's hack-and-leak playbook filtered into ransomware operations. The DNC breach's influence-amplification tactics eventually industrialized.
"These weren't black swans," Perlroth told the audience. "They were warning shots."
The Human Toll That Got Buried in the News Cycle
▶ Watch: Human Toll of Ransomware (20:01)
One of the most powerful sections of the keynote was Perlroth's account of covering the ransomware attack on University of Vermont Medical Center, where nurses described conditions comparable to the burn unit after the Boston Marathon bombing — chemotherapy canceled, procedures halted, patients turned away. She referenced the 78-year-old German woman who died in transit after being turned away from a hospital struck by ransomware during an aortic aneurysm, a case where legal causation could never be proven but the human reality was stark.
"We always seem to underestimate the human toll," she said.
The talk closed with a personal coda: Perlroth described breaking her toe on a hiking trip in the Dolomites during a lightning storm, only to find that the South Tyrol Alpine Rescue System had been hit with a ransomware attack. "There's no offline anymore," she said. "At some point you're going to need some help. And all of that help — at hospitals, in alpine rescue systems, your 911 operator — they're all digitized."
Disinformation as Cyber Weapon
▶ Watch: Rio Tinto Disinformation Story (28:02)
Perlroth described a striking anecdote from a 2022 private CEO summit. The then-CEO of Rio Tinto told her his company had prepared for a $50 million ransomware attack — but was blindsided by a $2.4 billion disinformation campaign targeting a lithium mine project in Serbia. Russian bots and trolls flooded social media with conspiracy theories (the mine was secretly for uranium, would rain sulfuric acid on Belgrade), personal attacks on the CEO, and targeted content about Serbia's prime minister. Tens of thousands of Serbians took to the streets. The mine was shut down.
"I was prepared for a fifty million dollar ransomware attack," the CEO told her. "I was not prepared for a two point four billion dollar disinformation attack."
Perlroth argued the same playbook has gone domestic: at RSA 2025, panelists were pulled from moderation slots because their employers feared federal contract retaliation if they were asked about the dismissal of CISA officials like Chris Krebs. The intimidation dynamic that once targeted Mexican journalists and UAE dissidents has arrived in American professional life — and it's being met, she said, with silence and a shrug.
Volt Typhoon and the Everything, Everywhere, All at Once Scenario
▶ Watch: Volt Typhoon and Chinese Infrastructure Pre-Positioning (36:02)
Perlroth spent considerable time on China's Volt Typhoon campaign, calling out its operational model: Chinese APTs are infiltrating American home routers through default passwords, misconfigurations, and legacy vulnerabilities, converting them into botnets, then using those botnets to conduct "living off the land" attacks on critical infrastructure. The attacks originate from servers in New Jersey or home routers in Indianapolis — precisely where U.S. intelligence agencies cannot legally operate.
She described interviewing Nick Lawler, general manager of a small Massachusetts utility serving 15,000 residents, who received a call from CISA and the FBI informing him that Volt Typhoon had been found in his systems. Together, they rooted it out. The story was meant as proof of concept: the public-private trust model works when it's allowed to function.
China's 1999 PLA doctrine — "Unrestricted Warfare" — outlines a strategy of attacking critical infrastructure to diminish an adversary's political will to fight, potentially winning a conflict without firing a bullet. "The thinking," Perlroth said, "is that if Xi really wants to reunify with Taiwan, he would do this to delay military mobilization or create chaos and panic and ultimately diminish our willingness to support an island seven thousand miles away."
She also pointed to China's national security laws that require citizens to turn over zero-days to the state, giving the government right of first refusal. The result: a new banner year for zero-days annually. She cited a recent Microsoft SharePoint vulnerability exploited against 400-plus targets, including the U.S. Nuclear Security Administration.
AI: A Narrow Window That Is Closing Fast
▶ Watch: AI and the Coming Inflection Point (42:03)
Perlroth positioned AI as the sharpest precipice the industry has ever faced. Early signals, she argued, favor offense: Microsoft Copilot was broken in June, Claude is winning hacking competitions, and tools like Expo are topping the HackerOne leaderboards. Ransomware groups are using AI to automate the kill chain — scanning for CVEs, identifying business-critical data, and running AI chatbots to maximize psychological pressure in ransom negotiations.
A Veracode report released just before the conference found that LLMs perform poorly at generating secure code, undercutting the promise that AI would help organizations escape technical debt. Meanwhile, deepfake audio is enabling million-dollar wire fraud, North Korean remote workers are using deepfake video to pass job interviews, and the attack surface is expanding to agentic workflows.
A McKinsey survey found that nearly 75% of companies claim to have adopted some form of AI, but only a quarter have moved beyond a pilot project. Perlroth argued that window — before AI is fully embedded in critical decision-making infrastructure — is the industry's last clean shot at getting security right by design.
"Once AI becomes embedded, once it's baked into our infrastructure, into our decision-making, into defense, the cost of failure only multiplies," she said. "And I worry, unlike some of the supply chain attacks we've seen to date, like SolarWinds, it will become irreversible."
Her prescriptions: shift left on AI security, secure unstructured data before it enters models, and deploy red teams at unprecedented scale. She also pointed to encouraging signs at the startup level — real-time deepfake detection, AI-induced hallucination traps for ransomware attackers during lateral movement, and 24/7 automated third-party risk interrogation tools.
Notable Quotes
"These weren't black swans. They were warning shots. And the fact that they worked spectacularly in some cases only emboldened our adversaries and cyber criminals."
— Nicole Perlroth [[18:01]](https://www.youtube.com/watch?v=4C1UL5sO_ME&t=1081s)
"We ignore these attacks at our own peril. They're not anomalies, they're signals, and they're picking up in innovation and in frequency."
— Nicole Perlroth [[40:03]](https://www.youtube.com/watch?v=4C1UL5sO_ME&t=2403s)
"We are not in the cybersecurity business anymore. We are in the saving civilization business."
— Joe Marshall, quoted by Perlroth [[50:03]](https://www.youtube.com/watch?v=4C1UL5sO_ME&t=3003s)
"The only way out is through, and the only way through is with courage."
— Nicole Perlroth [[54:03]](https://www.youtube.com/watch?v=4C1UL5sO_ME&t=3243s)
Key Takeaways
- Incidents are not anomalies — they are previews. Stuxnet, Shamoon, Sony, NotPetya, and SolarWinds were all previews of escalating techniques. Treating each one as exceptional rather than iterative has repeatedly left the industry flat-footed.
- Volt Typhoon is pre-positioning, not espionage. Chinese APT activity in U.S. utilities, water systems, and communications infrastructure follows the 1999 Unrestricted Warfare doctrine: disable civilian systems to erode political will, potentially winning a Taiwan conflict without direct military engagement.
- Disinformation is now a first-tier cyber weapon. The Rio Tinto case illustrates that narrative attacks can inflict multi-billion-dollar damage and are outpacing corporate and government playbooks. The same intimidation model is now operating domestically.
- The AI window is narrow and closing. Offensive AI capabilities are growing faster than defensive ones in key areas. Secure-by-design must be applied to AI systems from their infancy — not after deployment.
- Public-private trust is the irreplaceable foundation. The Ukraine cyber defense effort, the Volt Typhoon removal from Littleton's utility, and the pre-detonation discovery of Pipe Dream all depended on functioning trust between government and private sector. Eroding that trust — through workforce purges, silencing of officials, and institutional paralysis — is itself a national security threat.
Slides: No slides PDF was listed in the bundle for this keynote.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Perlroth is a skilled communicator and the Rio Tinto disinformation anecdote is genuinely striking — I hadn't heard it framed that way before. But this is a keynote-shaped Op-Ed from a journalist, not a security talk. The threat landscape tour covers nothing practitioners don't already know, and 'we need courage' is not an actionable takeaway.
Heather Calloway (CISO) — MUST SEE
Nicole Perlroth documented Volt Typhoon's pre-positioning in U.S. telecom and router infrastructure — staging for conflict, not conducting reconnaissance — the Rio Tinto $2.4 billion mine deal that was killed by a coordinated disinformation campaign without a single exploit, and AI as the force multiplier for influence operations at volume. The erosion of public-private trust means the intelligence sharing that defenders need most will be withheld precisely when they need it.