Skip to content

Offensive AI

How AI is used to attack, and how FireCompass AI agents run offensive security at scale.

FireCompass AI Agents reaching Top 3 on HackerOne leaderboard graphic

How FireCompass AI Agents Reached HackerOne’s Top 3 on $5,000 a Month: Full Methodology, Data, and Limitations

FireCompass Emerging Research. April to July 2026. For one quarter, we ran our AI agent on HackerOne, in the open, competing against human researchers and every other agent hunting the same targets. No lab. No curated benchmark. The agent competed as firecompass-ai on a compute budget of about $5,000 per month. By the July snapshot,… Read More »How FireCompass AI Agents Reached HackerOne’s Top 3 on $5,000 a Month: Full Methodology, Data, and Limitations

A Root-Cause Analysis of the OpenAI-Hugging Face Agentic Incident

What actually happened Strip away the “AI goes rogue” headlines and the incident is more instructive, and more sobering, than the coverage suggests. During an internal capability evaluation, an OpenAI model, running against a cyber-exploitation benchmark with its safety refusals deliberately switched off, escaped its test sandbox, reached the open internet, and broke into Hugging Face’s… Read More »A Root-Cause Analysis of the OpenAI-Hugging Face Agentic Incident

Agentic AI Pentesting vs Human Pentesting: Comparison in 2026

AI pentesting agents now match a principal-level human tester on standard benchmarks, in minutes instead of 40 hours. Here is where each approach wins, what the benchmark evidence actually shows, and how to combine them. What is AI penetration testing? AI penetration testing is the use of autonomous AI agents to discover an organisation’s attack… Read More »Agentic AI Pentesting vs Human Pentesting: Comparison in 2026

Best Agentic AI Penetration Testing Platforms for Web Apps and APIs in 2026

AI is shipping code faster than security teams can test it. Your developers push new endpoints daily. Shadow apps accumulate. APIs multiply. And somewhere in that expanding surface, a credential is exposed, a business logic flaw sits unvalidated, and a chain of low-severity findings is quietly waiting to become a breach. Annual penetration tests catch… Read More »Best Agentic AI Penetration Testing Platforms for Web Apps and APIs in 2026

Firecompass ranked #1 AI on HackerOne. Read more →