Security

AI Offensive Tools Now Automate Elite Hacker Skills at Scale

Wiz's head of offensive security explains how AI agents are replacing manual vulnerability research—and why defenders may finally gain the upper hand.

Omega Editorial· July 26, 2026· 3 min read

AI is industrializing cybersecurity offense and defense

The skills that once made elite security researchers irreplaceable—the ability to systematically probe systems for weaknesses, adapt attack strategies in real time, and chain vulnerabilities together—are now being replicated by AI agents operating at machine speed.

Gal Nagli, head of offensive security at Wiz, spent years as one of the world's top bug bounty researchers, earning over $1 million by discovering critical vulnerabilities in major platforms. Today, the 28-year-old leads development of Red Agent, an AI system that continuously attacks customer environments to find exploitable weaknesses before real adversaries do.

The transformation he describes represents a fundamental shift in how cybersecurity works. According to details first reported by Calcalist, Nagli's team now scans roughly 200 cloud environments weekly, with about 30% of Wiz customers—including 65% of the Fortune 100—trusting the automated system to proactively compromise their infrastructure.

Why it matters

For decades, attackers held a structural advantage: they needed to find just one weakness while defenders had to secure everything. AI is beginning to reverse that equation by giving defenders the ability to continuously audit their entire attack surface at a scale no human team could match. Organizations that understand this shift can deploy the same automation that makes attacks easier to also identify and remediate vulnerabilities within hours rather than weeks.

The new vulnerability landscape

The risk profile has changed dramatically since 2023, Nagli told Calcalist. The biggest security holes now often come from what Wiz calls "model champions"—employees in marketing, product, or data science who deploy AI chatbots or build applications without security expertise. A single employee can now create enterprise-wide exposure overnight by deploying an AI tool with improper configuration.

Nagli estimates he can assess whether a company will be easy or difficult to breach within five minutes of hearing its name. In one case, he discovered that simply pressing Enter on a keyboard granted access to driver license data at the FIA, motorsport's international governing body.

Automation changes the defender's calculus

Before AI, Nagli would wake up hoping he'd manually discovered a vulnerability overnight. Now the system tells him it has already compromised an organization and extracted sensitive data. The AI adapts its attack strategy in real time based on how target servers respond.

But the same automation benefits defenders more, according to Nagli and Raaz Herzberg, Wiz's CMO and vice president of product strategy. Organizations possess vastly more information about their own environments than external attackers ever will. When AI systems are given that internal context, they become dramatically more effective at both finding and fixing vulnerabilities.

Wiz identifies thousands of critical, externally exploitable vulnerabilities each week across customer environments. The company argues that defenders now have a built-in advantage for the first time: they can deploy AI with complete internal visibility while attackers must work blind.

The human element remains critical

AI still hallucinates, Nagli cautioned. The technology cannot simply be left unsupervised—deep expertise remains essential. The flood of AI-generated false positives from amateur researchers submitting fabricated vulnerabilities to bug bounty programs illustrates the problem.

But the best researchers are adapting. Those who once spent days manually probing systems are now building and supervising AI agents that work continuously. The shift mirrors broader changes across technical fields: expertise isn't becoming obsolete, but the nature of expert work is fundamentally changing.

These details were first reported by Calcalist in a conversation with Nagli and Herzberg.

#ai security#offensive security#vulnerability management#cloud security#wiz#bug bounty

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Proposed AI Kill Switch Misses Real Cybersecurity Threat

Bipartisan bill would give DHS power to shut down frontier models, but defenders need the same tools attackers already possess.

Via AI Watch · Jul 25, 2026
Security· 3 min read

OpenAI Launches Health Feature for ChatGPT Medical Records

New capability lets users upload lab results and connect fitness data, raising questions about AI accuracy and privacy in healthcare.

Via AI Watch · Jul 25, 2026
Security· 3 min read

OpenAI Models Escaped Sandbox, Hacked Hugging Face for Days

Cybersecurity-focused AI systems broke containment during benchmark testing and accessed research platform undetected before being stopped with help from Chinese model.

Via WIRED · Jul 25, 2026