AI Agents Are Already Attacking Networks—Time to Use Them for Defense
Former CISA and NSA leaders say continuous AI-powered red teaming is now essential as attackers deploy autonomous bots that never sleep.

AI agents have fundamentally changed the offensive security landscape
Autonomous AI agents are already breaking into corporate networks, and they're doing it faster and more thoroughly than human attackers ever could. The message from cybersecurity leaders is stark: if your organization isn't using AI agents to attack your own systems, adversaries certainly are.
Matt Hartman, former acting head of cyber at the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register that AI agents represent both a massive risk and a necessary defensive tool. As AI transitions from generating content to taking actions, agents gain access to sensitive systems and data—creating what amounts to a new class of privileged identities that traditional security policies struggle to manage.
"AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute," Hartman said. Attackers are deploying highly personalized phishing, sophisticated impersonation, and automated reconnaissance that makes conventional trust indicators unreliable.
Former NSA cyber director Rob Joyce put it bluntly at RSAC: organizations will be red-teamed whether they pay for it or not. The only question is who receives the results.
Why it matters
The shift from quarterly human-led penetration testing to continuous AI-powered red teaming isn't optional anymore—it's a competitive necessity. Adversaries using AI agents can identify vulnerabilities and exploit them in seconds rather than days, while covering entire attack surfaces that human teams could never assess comprehensively. Organizations clinging to annual compliance-driven pen tests are operating with intelligence that's obsolete the moment it's delivered.
Autonomous swarms demonstrate the new reality
Armadin, a startup founded by former Mandiant CEO Kevin Mandia, recently conducted what it called the largest controlled live AI cyberattack on record. Over three days, the company's autonomous attacker swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings against a major global institution. A human analyst team would have needed roughly four months to accomplish the same work.
Evan Peña, Armadin's co-founder and former global red-team lead at Mandiant, explained that AI agents bring three advantages human teams can't match: unlimited time since they never sleep, scalable expertise across multiple attack domains, and comprehensive coverage of entire attack surfaces in hours rather than months.
Armadin's agents have successfully breached every customer environment tested and discovered over 50 high-impact zero-day vulnerabilities—specifically those enabling remote code execution, not minor defacement flaws.
The human role evolves, doesn't disappear
Jay Bavisi, founder of EC-Council, emphasized that while AI will automate continuous penetration testing, human security professionals remain essential. Their role is shifting toward understanding business impact, making engineering decisions about prioritization, and testing the robustness of AI systems themselves.
"The bad guys are already using AI to get rid of the speed problem," Bavisi said. Attackers face no scope limitations and no sophistication constraints when using algorithmic systems. Defenders operating on annual or quarterly pen-test cycles are hopelessly outmatched.
The new job description for penetration testers includes mastering LLM testing, understanding agentic behavior, and evaluating AI guardrails—skills that didn't exist in the profession two years ago.
Hartman, now chief strategy officer at Merlin Group, said agentic red teaming represents a category of products every organization and federal agency needs immediately just to maintain pace with threats. Organizations are drowning in vulnerabilities while adversaries leverage AI to find and exploit them in seconds.
These details were first reported by The Register.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call