Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents

Pierluigi Paganini July 30, 2026

Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders.

Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders.

Beyond frontier models like Mythos, the report details how modern offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, Ethiack Nebula, and specialized LLMs like CyberStrike-OffSec-35B, have lowered the barriers to vulnerability identification and exploitation. Increasingly, these tools are becoming available to financially motivated cybercriminals, who would otherwise lack the technical abilities to carry out sophisticated attacks.

Artificial intelligence is rapidly transforming offensive security from isolated automation into autonomous, multi-agent systems capable of mapping attack surfaces, identifying vulnerabilities, validating exploits, and producing technical reports with minimal human intervention. According to Resecurity, AI agents are redefining how cybersecurity assessments are performed while also introducing new dual-use risks – leading to data breaches and network intrusions orchestrated via AI.

“Unlike traditional security automation, which executes predefined scripts, AI offensive agents operate as autonomous decision-making systems. They combine large language models, persistent memory, and specialized security tools to continuously plan, execute, evaluate, and adapt their actions throughout an assessment.” reads the report. “Rather than following a fixed sequence of commands, they dynamically adjust their strategy based on the results of previous actions, allowing them to perform complex, multi-stage security assessments with minimal human intervention.”

Resecurity examined the capabilities, architectures, and misuse of of modern AI offensive security tooling, highlighting how autonomous agents are reshaping both legitimate penetration testing and real-world cyber threats. Through case studies including FortiBleed, JadePuffer, and GTG-2002, it demonstrates that AI-assisted cyber operations are no longer theoretical.

While AI dramatically improves the speed, scale, and efficiency of offensive security, human expertise remains essential for creative exploitation, business logic analysis, and strategic decision-making. As autonomous AI continues to evolve, organizations should adopt a hybrid security model that combines AI-powered assessment with human oversight, continuous exposure validation, and strong defensive controls to prepare for increasingly automated cyber threats.

Resecurity forecasts cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders.

“AI-powered offensive security tools represent a genuine leap forward for defensive security. They can find and validate bugs faster, make pentesting more affordable, and help overworked security teams scale their work.” concludes the report. “But they are inherently dual-use. The same autonomous reconnaissance, exploitation, and post-exploitation engines designed for authorized testing can be pointed at real infrastructure by criminals, ransomware groups, and state actors with minimal modification.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AI offensive)



you might also like

leave a comment