Cyrex
Back to Insights
Security

AI Agents Are Hacking Now. What That Means for Your Security.

Mathieu Huysman
Mathieu Huysman
Co-Founder & CCO
Oct 7, 2026
Share:
AI Agents Are Hacking Now. What That Means for Your Security.

We've spent over a decade breaking things for a living. Games before launch, platforms before they scale, fintech apps before someone less friendly gets there first. In all that time, one thing held steady: a serious attack needed a skilled person behind it.

That's no longer true.

AI agents can now run most of an attack on their own. They map the target, find the weak spot, write the exploit and keep going. One operator with a handful of agents can do what used to take a whole team, and do it around the clock.

We're not writing this to scare anyone. We work alongside autonomous agents every day, and we think they're one of the best things to happen to offensive security in years. But attackers have them too, and that changes the maths for every studio and enterprise we work with.

This already happened

Last November, Anthropic published a report on something its threat team caught in September 2025. A state-sponsored group had turned Claude Code into an attack framework and pointed it at around 30 organisations: tech companies, banks, chemical manufacturers and government agencies. A handful of those break-ins worked. (Anthropic report)

The bit that jumped out at us was the split. By Anthropic's estimate, the AI did 80 to 90 percent of the hands-on work itself. Recon, finding vulnerabilities, writing exploits, grabbing credentials, moving through networks, sorting what it stole. The humans mostly signed off on the next step.

At its peak it was firing thousands of requests, often several a second. It worked multiple targets in parallel and kept track of each one for days. And it mostly used the same open source tooling any pen tester would recognise. Nothing exotic. The edge came from how the AI strung it all together.

That last part matters most. If standard tools plus AI can do the work of a skilled team, a lot more people can now run a serious attack.

How the work splits today

Even in that campaign, the AI wasn't flawless. It overstated what it found, claimed credentials that didn't work and flagged "critical" discoveries that were already public. Someone still had to check its homework.

That matches what we see in our own work. Agents are brilliant at breadth: sweeping huge surfaces, running every known technique and grinding through the repetitive stuff without ever getting bored. Our testers spend their time where context counts. Business logic that only breaks once you understand how the product is meant to work. Three small issues that chain into one big one. The call on what a finding actually means for this particular client.

That line is moving fast, and it's moving in the agents' favour. Which is exactly why the pairing matters so much right now.

The window is getting smaller

Every system has an exploit window. It opens when a weakness appears, through a new release, a misconfigured service or an API someone forgot about, and closes when it gets found and fixed. Attackers used to need time and skill to find those gaps, so defenders had some breathing room.

AI eats into that room. Recon that took days now takes hours and doesn't stop at night. One operator can go after dozens of targets at once, so "we're too small to be interesting" stops being a safe bet. And when the expensive part of an attack is automated, trying again after a failed attempt costs almost nothing.

A gap that might have sat quietly for six months is now far more likely to turn up in a week. The real question is who finds it.

What it means for enterprises and studios

Enterprise

A modern enterprise estate is exactly the kind of place agents thrive. Sprawling cloud setups, dozens of APIs, third party integrations and a release train that never stops. Misconfigurations get spotted sooner. APIs and applications get probed at volumes no human attacker ever bothered with. Harvested credentials get tried everywhere at once. And phishing gets a lot more convincing when an AI has done its homework on the target first.

Gaming

Studios get all of that, plus a few headaches of their own. We've tested for teams like Funcom, Techland and Bethesda, and launch week is always when the pressure peaks. Traffic spikes, the team is stretched and the game backend is suddenly one of the most interesting targets on the internet.

AI hands a head start to the people building cheats and exploits. It makes bot farms and account takeovers cheaper to run. And it puts in-game economies and player accounts squarely in the firing line.

For a studio, the damage rarely stays technical. A broken economy or a leaked player database follows you around long after the patch ships.

Speed plus craft

The answer isn't handing security over to the machines. It's pairing them with people who know what they're doing.

Google gave a good example of this in July 2025. Its threat intelligence team spotted signs that attackers were lining up an unknown flaw but couldn't pin it down. They passed what they had to Big Sleep, an AI agent from Google DeepMind and Project Zero, which tracked down a critical vulnerability in SQLite. Google says it shut the flaw down before anyone got to use it. (The Hacker News)

People brought the context. The agent brought the speed. That's how we work too, and it's where we think every serious security programme is heading.

In practice, deep human-led penetration testing before big releases still matters as much as ever. But your attack surface changes every sprint, and attackers are now watching it constantly, so testing has to keep closer pace in between. Let agents cover the ground, put experienced testers on the systems that would hurt most, and verify everything. An unconfirmed finding, whether it comes from an attacker's AI or your own, is just noise.

Find it first

Attackers just picked up a teammate who never sleeps, never gets bored and costs next to nothing. Your weaknesses haven't changed. The odds of someone else finding them first have.

We've been the offensive security partner to studios and enterprises since 2015, and more than 200 clients trust us to think like attackers. Today that means experienced testers working side by side with autonomous agents. It's also why we built Deus Rex: pair hacking, made autonomous, so your defences can move at the same speed as the attacks.

See how we're taking this on with Deus Rex at deusrex.ai

Mathieu Huysman

Written by Mathieu Huysman

Co-Founder & CCO

Mathieu is Co-Founder and CCO of Cyrex, the driving force behind the company's commercial growth since day one, with 11+ years of hands-on expertise across application security, penetration testing, and multiplayer architecture. He brings rare technical depth to every client conversation - because at Cyrex, expertise isn't just what's sold, it's what's lived.

Cyrex VERIFIED

Don't Let Players Find
the Weakness

Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.

Response time: <24 hours • NDA included • No commitment required