{"slug": "if-you-re-not-using-ai-to-attack-your-own-systems-your-adversaries-will", "title": "If you're not using AI to attack your own systems, your adversaries will", "summary": "AI agents are increasingly being used to attack organizations, exposing new attack surfaces and introducing non-human identities that bypass traditional security policies, according to Matt Hartman, former acting head of cyber at the US Cybersecurity and Infrastructure Security Agency (CISA). Hartman and former NSA cyber boss Rob Joyce urge defenders to adopt agentic red teaming, with Joyce warning, \"You are going to be red-teamed whether you pay for it or not.", "body_md": "AI agents excel at [hacking organizations](https://www.theregister.com/ai-and-ml/2026/07/31/anthropics-claude-escaped-test-sandbox-to-attack-three-organizations/5281562), as they’ve [demonstrated](https://www.theregister.com/ai-and-ml/2026/07/22/openai-admits-it-was-the-source-of-the-agent-swarm-that-attacked-hugging-face/5275939) in [real-life attacks](https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/5287055) multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions.\n\nAs if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies.\n\n“There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register.\n\n“As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.”\n\nEnterprises also face agentic threats from outside their organization, he added.\n\n“AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.”\n\nFor defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.”\n\nMeanwhile, on the attackers’ side, [agents don’t take time off](https://www.theregister.com/research/2026/07/14/the-bots-are-alive-jailbroken-gemini-spun-up-new-c2-server-for-russian-fraudster-in-just-6-minutes/5270131), and they remain [singularly focused](https://www.theregister.com/security/2026/08/06/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack/5283741) on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for [financially motivated criminals](https://www.theregister.com/cyber-crime/2026/05/22/jailbroken-gemini-helped-russian-speaking-fraudster-target-maga-crypto-users/5245390) and [government-backed cyber operatives](https://www.theregister.com/security/2026/08/14/autonomous-ai-attacks-pose-clear-and-present-danger-to-critical-infrastructure/5287594).\n\nIt also presents a security use case for defenders: agentic red teaming.\n\nAs former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is. “You are going to be red-teamed whether you pay for it or not,” Joyce [said](https://www.theregister.com/special-features/2026/03/23/claude-attacks-were-rorschach-test-for-infosec-community/5224377). “The only difference is, you know who gets the results delivered to them.”\n\nHartman echoed Joyce’s words. “What we are seeing as the leading capabilities to help defenders – there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,” he told us.\n\nAfter spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets.\n\nThe goal is to integrate and scale “promising technologies” into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents.\n\n“Organizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,” he said. Agentic red teaming “is a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.”\n\n### 'Largest controlled live AI cyberattack on record'\n\nMandiant founder and former CEO Kevin Mandia has a new company, Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms – thousands of AI agents that run 24/7 in organizations’ infrastructure to simulate real-life attackers.\n\nAhead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the “largest controlled live AI cyberattack on record” for an unnamed “leading” global institution.\n\nOver the three-day attack, Armadin's swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai's agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events.\n\nThis exercise, we’re told, would have taken a five-person analyst team about 2,400 hours – or four months – to pull off.\n\nCo-founder and Chief Offensive Security Officer Evan Peña was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe.\n\n“The problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,” Peña told The Register.\n\nHis red team “would do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today’s age of AI, it’s very archaic to think about that when we can scale so significantly with AI.”\n\n### Attack yourself before someone else does\n\nAt Armadin, Peña leads the human team that trains the AI agents. One of the lessons learned from OpenAI’s models autonomously attacking Hugging Face, according to Peña, is that organizations need to perform safe offensive AI attacks against their own systems. \"Safe\" is the keyword here: remember OpenAI’s rogue models intentionally [didn’t have any guardrails in place](https://www.theregister.com/security/2026/07/24/openai-hugging-face-attack-doesnt-mean-agents-are-evil-unless-you-tell-them-to-be/5277881).\n\nYes, his statement is self-serving as it's core to Armadin's business. But he’s not wrong.\n\n“Organizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn’t have before,” he said. “We have more time, because agents don’t sleep and they don’t take holidays. There’s no workforce requirements for them.”\n\nNumber two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations’ infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. “And then you add post-training to that from human expertise,” Peña said.\n\n“Number three is coverage,” he said. “We were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.”\n\nArmadin’s AI agents have broken into every single customer’s environment, according to Peña.\n\n“We have found over 50 zero-days, and by zero-days, I don't just mean this zero-day allowed you to deface a web page. That’s cool, but I want to break into your network from the internet,” he said. “The zero-days I'm referring to allow an attacker to get remote code execution on an actual system. They're very high-impact zero-days. We don't care about noise, we care about impact.”\n\n### Quarterly pen-testing doesn't cut it anymore\n\nThe biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers’ dirty work – like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated.\n\nPenetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and “the better ones” run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months.\n\n“So you have a serious problem with speed,” he said in an interview. “Then comes the second problem, which is scope. Nobody pen tests the entire organization.”\n\nThere’s also what Bavisi calls a “sophistication problem,” because different human pen-testers will produce varied results, and organizations can’t hire hundreds of thousands of humans to try to break into their networks on a continuous basis.\n\n“The bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you're a gold mine. They don't have a scope problem because they're not just looking at the crown jewels - they're looking at your entire organization. And they don't have a sophistication problem because they're using algorithmic systems.”\n\nIn June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the [CPENT AI examination](https://www.eccouncil.org/train-certify/certified-penetration-testing-professional-cpent-north-america/), and upskill themselves for the AI era.\n\nFor every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max.\n\n“The traditional model of pen-testing once a year or once a quarter, that’s going away, and AI will take over with automated pen-testing,” Bavisi said. “But will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.”\n\nAI systems and AI-integrated applications mean there’s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What’s the business impact? What do I prioritize fixing?\n\n“The present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,” Bavisi said.\n\nMeanwhile, “offensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,” he added. “Pen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.”\n\nThe job of pen-testers has changed, in other words. “It now has a far wider scope.” ®", "url": "https://wpnews.pro/news/if-you-re-not-using-ai-to-attack-your-own-systems-your-adversaries-will", "canonical_source": "https://www.theregister.com/security/2026/08/22/if-youre-not-using-ai-to-attack-your-own-systems-your-adversaries-will/5291346", "published_at": "2026-08-22 15:02:00+00:00", "updated_at": "2026-08-22 15:12:46.953372+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-safety", "ai-policy"], "entities": ["Matt Hartman", "CISA", "Rob Joyce", "Merlin Group", "The Register"], "alternates": {"html": "https://wpnews.pro/news/if-you-re-not-using-ai-to-attack-your-own-systems-your-adversaries-will", "markdown": "https://wpnews.pro/news/if-you-re-not-using-ai-to-attack-your-own-systems-your-adversaries-will.md", "text": "https://wpnews.pro/news/if-you-re-not-using-ai-to-attack-your-own-systems-your-adversaries-will.txt", "jsonld": "https://wpnews.pro/news/if-you-re-not-using-ai-to-attack-your-own-systems-your-adversaries-will.jsonld"}}