The research, published by Quantro Security’s Vulnerability Research Labs in partnership with Loginsoft, tested autonomous agents against 3,029 disclosed CVEs. The system successfully developed working proofs-of-concept for 72% of the flaws, a feat that would typically demand days or weeks of manual effort from human researchers. According to Quantro Chief Product Officer Mehul Revankar, the bottleneck of high-skilled talent is gone, meaning organizations can no longer rely on the assumption that certain vulnerabilities are too obscure to be weaponized.
Most concerning is the specific nature of the vulnerabilities targeted by these agents. Approximately 73% of the AI-exploitable flaws carry an EPSS score below 0.25—the common industry threshold for deprioritizing patches—while 89% are absent from CISA’s Known Exploited Vulnerabilities catalog. Quantro CEO Sasan Padidar argues that legacy metrics only measure the likelihood of a human attacker, failing to account for the speed and near-zero cost of AI-driven offense. To combat this, Quantro has released two free tools, AI-XI and AI-Recon, designed to help defenders evaluate their exposure through the perspective of an autonomous adversary.





Comments (0)
No comments yet. Be the first!