Security researchers and vendors documented rapid progress in using large language models and autonomous agents for offensive security testing, from early machine-learning-driven exploitation in Deep Exploit to newer multi-agent systems such as BLADE and Mastra-based workflows. In controlled demonstrations, these systems automated parts of reconnaissance, privilege-escalation analysis, credential discovery, lateral movement, and reporting, while broader evaluations found modern models increasingly capable of code understanding, vulnerability reasoning, and black-box web assessment tasks. The reporting also highlighted industry milestones such as AI-assisted pentesting tools reaching top bug bounty rankings and the growing use of agent patterns including ReAct, Plan-and-Execute, and orchestrated multi-agent designs for security assessments.
At the same time, the same body of work warned that AI-for-security deployments are creating new attack surfaces. Researchers observed internet scanning for exposed OpenAI-compatible Chat Completions endpoints, with likely goals including fingerprinting LLM servers, abusing unauthenticated inference, causing denial of service, and reaching downstream integrations such as RAG, tool calling, and URL fetching. Separate analysis warned that long-term memory in AI agents can preserve attacker-influenced instructions, stale conclusions, or misleading context across sessions, making provenance, freshness, access control, correction, and deletion critical controls. Across the studies, the message was consistent: AI agents are becoming more useful for security operations and testing, but their deployment requires strict governance, authentication, and safeguards against prompt injection, unstable execution, and low-quality automated findings.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
A technical article analyzed long-term memory mechanisms in AI agents and argued that poorly governed memory can preserve attacker-influenced instructions, stale conclusions, and repeated misjudgments. It compared approaches used by coding and general-purpose agents and stressed provenance, freshness, access control, correction, and deletion.
A technical article published results from 105 evaluations of seven LLMs on niche web application black-box security assessment tasks. It reported Claude Opus 4.6 and Claude Sonnet 4.6 as the strongest performers and emphasized the importance of harness design, context engineering, and tool integration.
Anthropic announced Claude Mythos as a privately accessible model claimed to surpass Opus and have strong cybersecurity capability. The source says Anthropic described Mythos as autonomously discovering previously unknown vulnerabilities through source-code static analysis.
An instructional article on AI agent design and context engineering for security workflows summarized design patterns, multi-agent architectures, and Mastra-based implementations. It explicitly states that its discussion reflects the state of the field as of March 2026.
A technical article surveyed LLMs and AI agents for security work, highlighting XBOW’s 2025 HackerOne milestone and discussing agent architectures, MCP, and the 2026 model landscape. It framed autonomous agents as increasingly relevant to penetration testing and web application assessment.
Mastra released Observational Memory as an event-based memory approach using Observer Agent and Reflector Agent components. A later article cites this release when discussing context management for AI agents.
A blog post documented reconnaissance traffic targeting externally exposed LLM services implementing OpenAI-style Chat Completions APIs. It also published two IP addresses associated with the probing and warned about abuse, DoS, and downstream integration risks.
The same reconnaissance activity against exposed LLM APIs was observed again on January 7, 8, and 9, 2026. The article links the traffic to likely endpoint discovery, fingerprinting, and abuse attempts against self-hosted LLM services.
Further reconnaissance traffic targeting exposed LLM services was observed the day after the initial sighting, indicating repeated probing activity.
The observer first saw scanning traffic targeting publicly exposed OpenAI-style Chat Completions endpoints. The requests were HTTP POSTs with JSON bodies containing model names, roles, prompts, and related parameters.
The autonomous LLM-based penetration testing tool XBOW reached the top position on HackerOne’s U.S. leaderboard. The source frames this as a notable milestone for AI-driven security testing.
A blog post described BLADE, a proof-of-concept autonomous penetration-testing system built with Microsoft AutoGen and seven specialized agents backed by GPT-4o-mini. In a controlled Ubuntu lab, it escalated privileges from an already-compromised host, found an SSH key, scanned the internal network, and successfully authenticated to a second host in about four minutes.
A technical evaluation tested GPT-4 on small web application code samples for source-code-based vulnerability detection and exploit generation. The author found useful logic comprehension and payload generation, but also significant false positives, false negatives, and scalability limits.
A technical blog post published research results for DeepExploit, describing it as a fully automated penetration testing system integrated with Metasploit and using reinforcement learning to pre-learn exploitation methods.
The DeepExploit project was presented at Black Hat EURO 2018 Arsenal, concluding the set of 2018 conference appearances listed in the source.
DeepExploit was presented at AV TOKYO 2018 Hive as another public showing of the automated pentesting research.
The DeepExploit research project was presented at CSS2018 during its 2018 outreach cycle.
DeepExploit was presented at DEF CON 26 AI Village as part of its 2018 conference appearances.
The DeepExploit project was presented at Black Hat USA 2018 Arsenal as one of its early public demonstrations.
A blog post described Deep Exploit as a beta tool that automates reconnaissance through exploitation by combining Metasploit with reinforcement learning. It explained the A3C-based design, learning and production modes, and published source code and usage information on GitHub.
The DeepExploit project was publicly presented at SECCON YOROZU 2018. A later article says the tool was exhibited there and received positive feedback.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcembsd.jp
Open sourceanthropic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.