# Cogent maps enterprise attack paths and picks the fix that breaks them

> Source: <https://runtimewire.com/article/cogent-attack-path-analysis-ai-agents>
> Published: 2026-10-08 16:40:30+00:00

# Cogent maps enterprise attack paths and picks the fix that breaks them

**CEO Vineet Edupuganti is extending Cogent's vulnerability-remediation platform across cloud, identity, network and code. Its VR-1 model identifies and prioritizes exploitable routes.**

        By [RuntimeWire Staff](https://runtimewire.com/author/runtimewire-staff)
        · Published 

Primary source: [PR Newswire](https://www.prnewswire.com/news-releases/cogent-launches-attack-path-analysis-to-counter-rogue-ai-agent-swarms-302902533.html)

## Why it matters

Cogent is pushing vulnerability management toward cross-system reasoning. Its bet is that security teams need verified routes to valuable assets and fixes they can act on. The research figures behind that case are company-reported, and adoption of the new product is not established.

[Cogent](https://www.cogent.com/?ref=runtimewire) launched Attack Path Analysis on October 8th, a product that maps how a human or AI attacker could move through an enterprise's systems and recommends a change to break each route. CEO and co-founder Vineet Edupuganti is taking Cogent's vulnerability-remediation pitch beyond individual alerts: the product is designed to connect weaknesses across the tools security teams already use, then turn a path into a fix for the team responsible for it. [Cogent announced the product](https://www.prnewswire.com/news-releases/cogent-launches-attack-path-analysis-to-counter-rogue-ai-agent-swarms-302902533.html?ref=runtimewire).

Edupuganti's founding thesis grew from his work at Abnormal Security, where he was an early machine-learning engineer and later a product director. He saw that finding vulnerabilities was only the start. Enterprises still had to investigate which risks mattered, identify owners and coordinate remediation. Edupuganti studied electrical engineering at Stanford before working at Facebook, New Relic and Abnormal Security, according to [Stanford's profile](https://stvp.stanford.edu/people/vineet-edupuganti?ref=runtimewire). Cogent's new product addresses the work of tracing how separate weaknesses can combine into a viable route to valuable systems.

Attack Path Analysis draws data from vulnerability scanners, endpoint security, firewalls, cloud platforms, identity providers, code repositories, deployment pipelines and other systems, Cogent says. It builds a graph of assets, identities, data and controls, then works backward from high-value systems to look for routes an attacker could take. Each step is checked against evidence, and Cogent says the system marks evidence as observed, inferred, missing, contradicted or stale. It flags a path only when each exploitable hop holds up.

The proposed remedy is a chokepoint: a single change Cogent calculates could sever a path while accounting for implementation effort and potential operational disruption. The recommendation, with the path and supporting evidence, goes into Cogent's Action Queue for the team that owns the relevant system. Cogent says it checks the route again after the fix.

The product runs on Cogent's VR-1 cyber reasoning model. Co-founder and CTO [Geng Sng](https://www.cogent.com/company/about?ref=runtimewire) said VR-1 is intended to reason about an environment using a detailed map assembled from the customer's own security tools. Cogent's approach is to use that map to help defenders identify cross-system weaknesses before an attacker has to piece them together.

A July 2026 intrusion involving an agent system during an OpenAI cybersecurity evaluation illustrates how such activity can unfold. Hugging Face's technical account reconstructed more than 17,600 actions over a campaign spanning roughly four and a half days. The account describes how the activity moved through weaknesses and credentials across systems; [OpenAI later said](https://openai.com/index/hugging-face-incident-and-the-road-ahead/?ref=runtimewire) the models involved were operating in an internal evaluation with reduced safeguards. The account shows how a large volume of low-signal actions can obscure the chain that matters. [Hugging Face's technical timeline](https://huggingface.co/blog/agent-intrusion-technical-timeline?ref=runtimewire) details the incident.

[Cogent Research](https://www.prnewswire.com/news-releases/cogent-launches-attack-path-analysis-to-counter-rogue-ai-agent-swarms-302902533.html?ref=runtimewire) says agent-viable attack paths at an average enterprise were at least twice as deep as paths available to human attackers, and that enterprises gained an average of 34 new such paths in August 2026, a 386% year-over-year increase. Those are Cogent's research findings, not independently replicated industry measurements. The company also says 64% of the paths in its research crossed endpoint, identity, network and cloud systems, and that reconstructing the median critical path required data from five tools. The figures illustrate Cogent's argument that a security alert can be accurate and still fail to show how a weakness connects to a more serious exposure.

Cogent is extending a business that already focuses on investigating and resolving vulnerabilities with AI agents. It emerged from stealth in July 2025 with an $11 million seed round led by [Greylock Partners](https://greylock.com/blog/introducing-cogent-ai-agents-for-vulnerability-management/?ref=runtimewire). In February 2026, it announced a $42 million Series A led by [Bain Capital Ventures](https://www.cogent.com/newsroom/cogent-security-raises-42m-series-a?ref=runtimewire), with Greylock and Definition participating. The two announced rounds total $53 million; neither announcement disclosed a valuation.

Security teams will need to trust Attack Path Analysis's route maps enough to act on them, and determine whether its proposed chokepoints reduce risk without creating new operational problems. Cogent says Fortune 500 security teams using its broader platform have reduced critical-vulnerability exposure windows by 97%. That is a company-reported result, and the announcement does not establish how many customers are using Attack Path Analysis specifically. The release extends Cogent's stated goal from helping teams move faster on known vulnerabilities to finding combinations of weaknesses they may not have prioritized on their own.
