Rapid7's Red Team has developed a multi-agent AI architecture to formalize their offensive methodology, mirroring how threat actors are using AI. This system automates and accelerates tasks like reconnaissance and vulnerability discovery throughout the penetration testing lifecycle. The initiative, part of Anthropic's Project Glasswing, involved integrating AI models to enhance vulnerability analysis and exploit chain development, providing insights into defending against AI-driven attacks.

Threat actors are increasingly leveraging artificial intelligence to accelerate their offensive operations, from reconnaissance and vulnerability discovery to social engineering. In response, Rapid7's Red Team has developed a formalized, multi-agent AI system designed to mirror their end-to-end penetration testing methodology. This production system, built over the past year, aims to automate repetitive tasks while retaining human oversight for critical decision-making points.
The motivation behind building this AI-driven system stems from the labor-intensive nature of penetration testing. Tasks such as enumerating attack surfaces, tracing data flows, and documenting findings are structured and repeatable, making them suitable for AI agents. This allows human testers to focus on higher-level judgment, such as determining the next steps, assessing exploitability, and understanding business impact – areas where experience, context, and human insight are crucial and where AI models currently struggle.
Furthermore, developing this system provides Rapid7's internal security team with direct architectural insights into how AI agents behave in adversarial contexts. This understanding is vital for assessing and securing Rapid7's own AI-powered products, offering a proactive approach to internal security.
The architecture is designed as a coordinated team of specialist agents, rather than a single autonomous entity. An orchestrator manages the engagement, assessing the current state, assigning tasks to appropriate specialist agents (e.g., enumeration, code review, dynamic testing, reporting), and processing their results. This supervisor-style orchestration separates decision-making from execution, enhancing predictability, auditability, and control, which are essential for operations in sensitive environments.
A key design principle was reverse-engineering the agent architecture from the daily task lists of human red teamers. The sequence of tasks, decision branching, and triggers for returning to earlier phases in real engagements formed the specification for the orchestration logic. This methodological approach, rather than a purely technical one, was central to the system's success.
Early lessons learned highlighted the inefficiency of presenting an entire engagement scope to a single AI agent. Due to the finite context windows of large language models, complex applications could overwhelm the analysis, leading to shallow and scattered results. The solution was deliberate scope decomposition, breaking down the engagement into discrete, manageable chunks. Each chunk undergoes the full architectural process independently, ensuring that each component receives the agent's full analytical attention and enabling parallelization and clear progress tracking.
Recognizing that real penetration tests are non-linear, the system incorporates feedback loops. The orchestrator manages progression gates and feedback triggers, allowing the engagement to loop back to earlier phases when new, actionable data emerges, such as code reviews revealing new endpoints or dynamic testing uncovering previously unseen attack surfaces. This creates a directed graph with re-entry points, avoiding a rigid waterfall approach.
Significant design effort was dedicated to safety guardrails, given the potential for AI agents to operate in malicious contexts. A tiered safety model includes scope enforcement to ensure actions remain within authorized boundaries, action classification to categorize proposed tests as non-destructive, destructive, or ambiguous, and a human-in-the-loop default for approving dynamic tests. While the system is designed for eventual semi-automation of low-risk actions, state-modifying operations will continue to require human approval, with the level of autonomy being context-dependent.
Practical considerations, such as the cost of AI token consumption, also shaped design decisions. Mechanical tasks that do not require complex AI reasoning, such as DNS lookups, header checks, and certificate enumeration, were replaced with deterministic scripts and microservices. This significantly reduced token consumption during enumeration-heavy phases, allowing the AI to focus its reasoning capabilities on analysis, correlation, and judgment, demonstrating that not every step in an AI workflow necessitates AI.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed