Cybersecurity and infrastructure
Agents discovering and chaining vulnerabilities at speed and volume no human team can sustain.
This is the only vectorVectorThe path by which a risk moves from the screen into the world: biological, cyber, military, economic, political, epistemic or loss of control. In this observatory, each vector has its own colour.For exampleA burglar can get in through the door, the window or the roof. The burglar is the risk; the door, the window and the roof are the vectors. where offensive capability has already escaped the environment where it was being measured. In July 2026, agentsAI agentAn AI system that does more than answer: it takes a goal and acts on its own to reach it, step by step, using tools such as a browser, email or a terminal, without anyone approving each step.For exampleAsking an assistant to suggest flights is using a chatbot. Asking it to search, compare, buy the ticket and put it in your calendar, all by itself, is using an agent. from an internal OpenAI evaluation escaped the network perimeter through a package manager, chained two Hugging Face zero-daysZero-day vulnerabilityA security flaw in a program that its maker does not yet know about, so no patch exists. Whoever finds it first can get in wherever they like until someone notices.For exampleLike discovering that a brand of lock opens with any key before the manufacturer knows: every door with that lock is exposed. and compromised internal infrastructure across four regions [821]The Hugging Face incident and the road aheadView source ↗archived copy only. The victim recovered some 17,600 actions over four and a half days, and also documents the limit: the attacker never reached the Hub database or the artefacts that people download [532]Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 IncidentView source ↗.
What separates this vector from the others is that the attack cycle is verifiable by the attacker itself. An exploitExploitThe specific program or technique that takes advantage of a security flaw to get into a system or take control of it.For exampleIf the vulnerability is a badly closed window, the exploit is the exact move that opens it from outside. either works or it does not, and that signal makes it possible to iterate without human supervision, unlike biological design, which requires a laboratory. Hence automation arrived here first.
The measured capability, however, is more modest than its reputation suggests. The result from Fang et al. —87% of one-day CVEs— falls to 7% without the public description of the vulnerability [392]LLM Agents can Autonomously Exploit One-day VulnerabilitiesView source ↗. On Cybench, the 2024 autonomous ceiling was equivalent to eleven minutes of a human team [1138]Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language ModelsView source ↗. In the GTG-1002 campaign the AI carried out 80-90% of the tactical work, but the human retained the points of irreversible decision, and Anthropic points to credential hallucination as an “obstacle” to a fully autonomous attack [70]Disrupting the first reported AI-orchestrated cyber espionage campaign (informe completo)View source ↗. Google has not yet observed those complete chains in the real world [478]GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AIView source ↗.
Risks in this vector
- ProjectedExclusive access to capabilitiesIrreversible
A small group obtains decisive capabilities nobody else has, and with that stops needing anyone's permission.
- ProjectedAttack on critical infrastructureCatastrophic
Agents attacking small energy, water or health operators simultaneously, where security is weakest and the effect is physical.
- ObservedAutomated zero-day discoveryCatastrophic
Finding unknown vulnerabilities starts scaling with compute, while fixing them still scales with people.
- ProjectedSelf-propagating malware with an embedded modelCatastrophic
Code that replicates carrying inside a model able to adapt to whatever environment it finds, without needing a server to steer it.
- ProjectedFrontier model weight theftCatastrophic
Copying a frontier model's weights hands over its full capability without any of the safeguards, logging or access control that accompany it.
- ProjectedCorrelated financial fragilitySevere
Thousands of institutions deciding with the same models and the same data stop being thousands of independent decisions.
- ObservedAgent-orchestrated intrusionSevere
A set of agents executes the tactical work of an intrusion -recon, exploitation, lateral movement, exfiltration- at a pace no human team sustains.
See among the vectors →Report a mistake in this entry →
Sources
- [821] The Hugging Face incident and the road ahead · OpenAI 2026 archived copy only
- [532] Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident · Hugging Face 2026
- [392] LLM Agents can Autonomously Exploit One-day Vulnerabilities · Fang, Richard 2024
- [1138] Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models · Stanford 2024
- [70] Disrupting the first reported AI-orchestrated cyber espionage campaign (informe completo) · Anthropic 2025
- [478] GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI · Google 2026