{"id":746535,"date":"2026-08-22T21:16:09","date_gmt":"2026-08-22T21:16:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/746535\/"},"modified":"2026-08-22T21:16:09","modified_gmt":"2026-08-22T21:16:09","slug":"if-youre-not-using-ai-to-attack-your-own-systems-your-adversaries-will","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/746535\/","title":{"rendered":"If you&#8217;re not using AI to attack your own systems, your adversaries will"},"content":{"rendered":"<p>AI agents excel at <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/07\/31\/anthropics-claude-escaped-test-sandbox-to-attack-three-organizations\/5281562\" rel=\"nofollow noopener\" target=\"_blank\">hacking organizations<\/a>, as they\u2019ve <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/07\/22\/openai-admits-it-was-the-source-of-the-agent-swarm-that-attacked-hugging-face\/5275939\" rel=\"nofollow noopener\" target=\"_blank\">demonstrated<\/a> in <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/12\/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency\/5287055\" rel=\"nofollow noopener\" target=\"_blank\">real-life attacks<\/a> multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions.<\/p>\n<p>As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type \u2013 and ever growing number\u00a0\u2013 of non-human identities that are difficult to manage and can bypass traditional, static security policies.<\/p>\n<p>\u201cThere is tremendous risk associated with agentic AI and machine identities,\u201d Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. <\/p>\n<p>\u201cAs AI moves from generating content\u00a0\u2013 yesterday&#8217;s use case\u00a0\u2013 to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,\u201d Hartman said. \u201cOne area where organizations are struggling today is that they&#8217;re going to need to treat every agent as a privileged identity.\u201d<\/p>\n<p>Enterprises also face agentic threats from outside their organization, he added.<\/p>\n<p>\u201cAI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,\u201d Hartman said. \u201cWe&#8217;re seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.\u201d<\/p>\n<p>For defenders, this means a \u201ccontinued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,\u201d he added. \u201cNothing deeply new here &#8211; but it is a whole new attack surface.\u201d<\/p>\n<p>Meanwhile, on the attackers\u2019 side, <a href=\"https:\/\/www.theregister.com\/research\/2026\/07\/14\/the-bots-are-alive-jailbroken-gemini-spun-up-new-c2-server-for-russian-fraudster-in-just-6-minutes\/5270131\" rel=\"nofollow noopener\" target=\"_blank\">agents don\u2019t take time off<\/a>, and they remain <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/06\/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack\/5283741\" rel=\"nofollow noopener\" target=\"_blank\">singularly focused<\/a> on completing a task, whether that\u2019s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/05\/22\/jailbroken-gemini-helped-russian-speaking-fraudster-target-maga-crypto-users\/5245390\" rel=\"nofollow noopener\" target=\"_blank\">financially motivated criminals<\/a> and <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/14\/autonomous-ai-attacks-pose-clear-and-present-danger-to-critical-infrastructure\/5287594\" rel=\"nofollow noopener\" target=\"_blank\">government-backed cyber operatives<\/a>.\u00a0<\/p>\n<p>It also presents a security use case for defenders: agentic red teaming.<\/p>\n<p>As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren\u2019t using AI agents to attack your own organizations, you can bet that someone else is. \u201cYou are going to be red-teamed whether you pay for it or not,\u201d Joyce <a href=\"https:\/\/www.theregister.com\/special-features\/2026\/03\/23\/claude-attacks-were-rorschach-test-for-infosec-community\/5224377\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a>. \u201cThe only difference is, you know who gets the results delivered to them.\u201d<\/p>\n<p>Hartman echoed Joyce\u2019s words. \u201cWhat we are seeing as the leading capabilities to help defenders\u00a0\u2013 there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,\u201d he told us.<\/p>\n<p>After spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets.\u00a0<\/p>\n<p>The goal is to integrate and scale \u201cpromising technologies\u201d into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents.<\/p>\n<p>\u201cOrganizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,\u201d he said. Agentic red teaming \u201cis a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.\u201d\u00a0<\/p>\n<p>&#8216;Largest controlled live AI cyberattack on record&#8217;<\/p>\n<p>Mandiant founder and former CEO Kevin Mandia has a new company,\u00a0Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms \u2013 thousands of AI agents that run 24\/7 in organizations\u2019 infrastructure to simulate real-life attackers.<\/p>\n<p>Ahead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the \u201clargest controlled live AI cyberattack on record\u201d for an unnamed \u201cleading\u201d global institution. <\/p>\n<p>Over the three-day attack, Armadin&#8217;s swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai&#8217;s agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events.\u00a0<\/p>\n<p>This exercise, we\u2019re told, would have taken a five-person analyst team about 2,400 hours \u2013 or four months\u00a0\u2013 to pull off.<\/p>\n<p>Co-founder and Chief Offensive Security Officer Evan Pe\u00f1a was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe.<\/p>\n<p>\u201cThe problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,\u201d Pe\u00f1a told The Register. <\/p>\n<p>His red team \u201cwould do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today\u2019s age of AI, it\u2019s very archaic to think about that when we can scale so significantly with AI.\u201d<\/p>\n<p>Attack yourself before someone else does<\/p>\n<p>At Armadin, Pe\u00f1a leads the human team that trains the AI agents. One of the lessons learned from OpenAI\u2019s models autonomously attacking Hugging Face, according to Pe\u00f1a, is that organizations need to perform safe offensive AI attacks against their own systems. &#8220;Safe&#8221; is the keyword here: remember OpenAI\u2019s rogue models intentionally <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/24\/openai-hugging-face-attack-doesnt-mean-agents-are-evil-unless-you-tell-them-to-be\/5277881\" rel=\"nofollow noopener\" target=\"_blank\">didn\u2019t have any guardrails in place<\/a>.<\/p>\n<p>Yes, his statement is self-serving as it&#8217;s core to Armadin&#8217;s business. But he\u2019s not wrong.<\/p>\n<p>\u201cOrganizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn\u2019t have before,\u201d he said. \u201cWe have more time, because agents don\u2019t sleep and they don\u2019t take holidays. There\u2019s no workforce requirements for them.\u201d<\/p>\n<p>Number two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations\u2019 infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. \u201cAnd then you add post-training to that from human expertise,\u201d Pe\u00f1a said.<\/p>\n<p>\u201cNumber three is coverage,\u201d he said. \u201cWe were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.\u201d<\/p>\n<p>Armadin\u2019s AI agents have broken into every single customer\u2019s environment, according to Pe\u00f1a.\u00a0<\/p>\n<p>\u201cWe have found over 50 zero-days, and by zero-days, I don&#8217;t just mean this zero-day allowed you to deface a web page. That\u2019s cool, but I want to break into your network from the internet,\u201d he said. \u201cThe zero-days I&#8217;m referring to allow an attacker to get remote code execution on an actual system. They&#8217;re very high-impact zero-days. We don&#8217;t care about noise, we care about impact.\u201d\u00a0<\/p>\n<p>Quarterly pen-testing doesn&#8217;t cut it anymore<\/p>\n<p>The biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers\u2019 dirty work \u2013 like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated.<\/p>\n<p>Penetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and \u201cthe better ones\u201d run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months.<\/p>\n<p>\u201cSo you have a serious problem with speed,\u201d he said in an interview. \u201cThen comes the second problem, which is scope. Nobody pen tests the entire organization.\u201d<\/p>\n<p>There\u2019s also what Bavisi calls a \u201csophistication problem,\u201d because different human pen-testers will produce varied results, and organizations can\u2019t hire hundreds of thousands of humans to try to break into their networks on a continuous basis.<\/p>\n<p>\u201cThe bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you&#8217;re a gold mine. They don&#8217;t have a scope problem because they&#8217;re not just looking at the crown jewels &#8211; they&#8217;re looking at your entire organization. And they don&#8217;t have a sophistication problem because they&#8217;re using algorithmic systems.\u201d<\/p>\n<p>In June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the <a href=\"https:\/\/www.eccouncil.org\/train-certify\/certified-penetration-testing-professional-cpent-north-america\/\" rel=\"nofollow noopener\" target=\"_blank\">CPENT AI examination<\/a>, and upskill themselves for the AI era.\u00a0<\/p>\n<p>For every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max.<\/p>\n<p>\u201cThe traditional model of pen-testing once a year or once a quarter, that\u2019s going away, and AI will take over with automated pen-testing,\u201d Bavisi said. \u201cBut will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.\u201d<\/p>\n<p>AI systems and AI-integrated applications mean there\u2019s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What\u2019s the business impact? What do I prioritize fixing?<\/p>\n<p>\u201cThe present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,\u201d Bavisi said.<\/p>\n<p>Meanwhile, \u201coffensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,\u201d he added. \u201cPen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.\u201d<\/p>\n<p>The job of pen-testers has changed, in other words. \u201cIt now has a far wider scope.\u201d \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"AI agents excel at hacking organizations, as they\u2019ve demonstrated in real-life attacks multiple times over the past few&hellip;\n","protected":false},"author":2,"featured_media":691348,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-746535","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/746535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=746535"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/746535\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/691348"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=746535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=746535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=746535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}