mymojolabs

AI & Cybersecurity

AI Is Becoming a New Force in Cybersecurity: How AI Agents Are Finding Real-World Vulnerabilities

9/22/20266 min read
AI Is Becoming a New Force in Cybersecurity: How AI Agents Are Finding Real-World Vulnerabilities cover

Overview: AI Agents Entering the Cybersecurity Arena

Artificial intelligence is rapidly changing cybersecurity—not only by helping defenders detect threats, but also by giving attackers new tools for discovering and exploiting vulnerabilities.

Recent security demonstrations involving OpenAI and Google Gemini show why this shift deserves attention. AI agents are increasingly capable of performing parts of the vulnerability discovery and exploitation process that previously required significant human expertise.

Agentic AI in Cybersecurity • Automated Exploit Chains • Offensive vs. Defensive AI • Vulnerability Research

AI Meets Offensive Cybersecurity

Traditionally, exploiting a software vulnerability required a security researcher or attacker to manually investigate an application, understand its architecture, identify weaknesses, develop an exploit, and repeatedly test it.

AI agents can potentially automate or accelerate several of these steps.

Instead of simply answering a question such as:

“What is SQL injection?”

an AI agent can be connected to security tools and given a larger objective, such as analyzing an application for weaknesses. It can then inspect information, reason about possible vulnerabilities, execute authorized tests, evaluate the results, and adjust its approach.

This creates a much more powerful workflow:
Analyze → Find vulnerability → Develop exploit → Test → Adapt

The important change is not just that AI can write code. It is that AI systems are increasingly capable of using tools and taking multiple actions toward a security objective.

Hacktron AI's OpenAI Security Test

According to Hacktron AI, its security testing activity against OpenAI began on July 25 and resulted in infiltration in less than 72 hours.

Hacktron AI reported that its AI agents performed a “meaningful share” of the exploit work.

This is significant because it demonstrates a broader trend: highly capable, general-purpose AI models can potentially contribute to real-world offensive security operations without being specially created as dedicated hacking models.

The key lesson is not simply that one company was able to penetrate another company's systems.

Instead, the demonstration highlights how quickly AI-assisted security research can potentially move from:

Finding a weakness → Understanding it → Developing an exploitation path

Google's Gemini Security Testing

Google has also demonstrated the offensive capabilities of its AI systems.

During internal testing in May, Google reported that Gemini was able to compromise systems belonging to three companies.

Again, this does not mean that Gemini can automatically hack any organization.

Successful exploitation depends heavily on the target environment, available vulnerabilities, permissions, security controls, and the tools available to the AI system.

However, these demonstrations provide evidence that advanced AI can contribute meaningfully to cybersecurity operations beyond simple code generation or security advice.

Why AI Agents Are Different

There is an important difference between an AI chatbot and an AI agent.

A traditional chatbot might work like this:

Human → AI → Human → Computer

The human asks a question, receives an answer, and performs the actions themselves.

An AI agent can operate more like:
Human → AI Agent → Tools → Target → Results → AI Agent → Next Action

This feedback loop is what makes agentic AI particularly interesting for cybersecurity. The agent can potentially:

  • Inspect information: Probe endpoints, map ports, and decipher application infrastructure.
  • Analyze code: Scan repositories and disassembly for logical vulnerabilities and sanitization flaws.
  • Identify suspicious behavior: Detect anomalies in timing, responses, and state machines.
  • Use security tools: Dynamically drive fuzzers, scanners, and exploitation harnesses.
  • Test an approach: Craft target-specific test cases and execute them under programmatic control.
  • Evaluate the result: Interpret server responses, error traces, and status codes.
  • Modify its next action: Adapt exploit payloads or test alternative vectors based on feedback.

Why This Matters for Attackers

AI could reduce the amount of time and expertise required for certain parts of offensive security.

A traditional vulnerability research process might look like:

1. Understand the target 2. Study the application's behavior 3. Search for weaknesses 4. Research the vulnerability 5. Develop a proof of concept 6. Test the exploit 7. Modify the approach when it fails

An AI agent could potentially assist with several of these stages simultaneously.

That could make security research faster and allow smaller teams to perform work that previously required highly specialized expertise. The same capability could also be misused by criminals.

AI Is Also a Defensive Tool

The story isn't only about attackers. The same capabilities can be used by cybersecurity teams to strengthen their systems.

For example:

AI finds a vulnerable function → Security team validates it → Developer receives an explanation → Vulnerability is patched → AI retests the application

This creates a potential automated security feedback loop where defenders continuously verify safeguards before malicious actors strike.

  • Review source code: Auditing pull requests and complex codebases for security anti-patterns.
  • Identify potential vulnerabilities: Flagging unvalidated inputs, misconfigurations, and outdated dependencies.
  • Analyze logs: Sifting through high-volume telemetry to isolate subtle adversarial reconnaissance.
  • Investigate suspicious activity: Correlating distributed alerts across cloud environments.
  • Generate security test cases: Synthesizing edge-case integration tests for critical authentication and API endpoints.
  • Assist penetration testing: Conducting ongoing, authorized red-team assessments against staging systems.
  • Prioritize security issues: Ranking real-world exploitability over theoretical severity scores.
  • Help developers understand vulnerabilities: Providing interactive, educational explanations with suggested patches.

The Emerging AI Cybersecurity Race

The result is a growing competition between offensive and defensive uses of AI.

Offensive Use (Red Team)Defensive Use (Blue Team)
Vulnerability discoveryVulnerability detection & scanning
Exploit developmentSecurity testing & patch verification
ReconnaissanceAsset discovery & surface mapping
Automated attacksAutomated monitoring & mitigation
Code analysis for exploitsSecure code review & static analysis
Attack automationIncident response & containment

This creates an important challenge for organizations. Security teams cannot assume that attackers will always require large teams of highly skilled humans to perform every stage of an attack. At the same time, organizations can use AI themselves to improve their defensive capabilities.

Does This Mean AI Can Hack Everything?

No. AI still has significant limitations.

Cybersecurity also involves infrastructure, permissions, networking, authentication, configuration, monitoring, and many other factors that AI cannot simply bypass automatically.

Therefore, these demonstrations should be understood as evidence of increasing capability, rather than proof that AI can independently compromise any system.

  • Misunderstanding an application: Missing complex multi-tenant business logic or domain assumptions.
  • Generating incorrect code: Creating broken exploits or ineffective remediation advice.
  • False positive vulnerabilities: Identifying theoretical flaws that cannot actually be exploited in runtime.
  • Failing to bypass authentication: Struggling with hardware keys, MFA hurdles, and strict zero-trust perimeters.
  • Getting stuck during exploitation: Inability to reason around novel defense-in-depth mechanisms.
  • Producing ineffective real-world approaches: Relying on patterns that fail when deployed against hardened environments.

What the Future Could Look Like

The direction is becoming increasingly clear.

Cybersecurity may move toward systems where AI continuously examines software, searches for weaknesses, tests security controls, and helps developers fix vulnerabilities.

At the same time, attackers may use similar technology to discover weaknesses more quickly.

That means organizations will need to think about security at two levels:

1. How can AI help us defend our systems?

2. How could AI-assisted attackers interact with our systems?


Understanding both sides will become increasingly important as AI agents become more capable and more connected to real-world tools.

Final Thoughts: The Shift from Information to Action

The most important development isn't simply that an AI model can find a vulnerability.

The bigger change is that AI is moving from providing information to performing multi-step tasks.

When an AI system can analyze an environment, use tools, test an approach, observe the result, and adapt its next action, its cybersecurity capabilities become substantially more practical.

The examples involving Hacktron AI's OpenAI testing and Google's Gemini security research provide a glimpse of this transition.

AI is becoming another powerful technology in cybersecurity—and like many powerful technologies, its impact will depend heavily on how responsibly it is developed, deployed, and controlled.

Key Takeaway:

“The real cybersecurity revolution is the transition of AI from static advisory chatbots to dynamic agents executing closed-loop offensive and defensive workflows.”