Quantro Security Report Finds AI Agents Can Exploit Vulnerabilities in Minutes for Under $3
Quantro Security announced in a press release that autonomous AI agents can convert publicly disclosed vulnerabilities into verified working exploits in about 11 minutes for a median compute cost of $2.83. The findings are based on testing 3,029 disclosed CVEs, where AI agents successfully built and verified exploits for 2,183 of them, or 72 percent.
The study used the Quantro Exploit Harness, a system of AI agents that automatically ingests vulnerabilities, develops proofs of concept, and verifies successful execution without human input. Independent verification of the methodology and findings was conducted by Loginsoft.
The report highlights that 73 percent of the AI exploitable vulnerabilities carried an Exploit Prediction Scoring System score below 0.25, indicating that these flaws are often deprioritized by enterprise patching programs. Additionally, 89 percent of these were missing from the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.
To help organizations assess and mitigate these threats, Quantro Security is releasing two free tools, AI-XI (AI Exploitability Index) and AI-Recon (AI Native Exposure Scanner), designed to evaluate exploitability and exposure through the perspective of an AI attacker.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly, AI Policy Brief or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 16 Cohesity Adds AI Agent Backup and Recovery to Data Cloud Sep 15 Hexnode Introduces Synapse for IT and Security Operations Sep 15 Cisco Expands Splunk AI for Private and Isolated Environments Sep 15 Zip Security Joins CrowdStrike Coalition to Protect Small Businesses Sep 14 Open Secure AI Alliance Joins Linux FoundationMore from AI Safety
Sep 16 Trump calls AI safety fears a hoax during live call with NVIDIA CEO Sep 15 Project Liberty and Partners Launch Pro-Human AI Coalition Sep 15 Gensyn Releases Auditable open-1b AI Model Sep 15 King Charles to Host AI Leaders for Safety Talks Sep 15 China's Foreign Ministry Answers AI Slowdown CallsCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Whitepaper
Tensordyne Napier: What If One Rack Could Do the Work of Nine?
Tensordyne
This Tensordyne whitepaper presents Napier, an inference-focused AI processor and rack-scale system based on the company’s TDN Math logarithmic number system. It examines infrastructure requirements for large mixture-of-experts and agentic models, compares major inference architecture approaches, and details the TDN AIP processor, TDN72 pod, TDN Link fabric, and Napier Ultra configuration. The paper reports simulation-based performance, cost, and accuracy-validation results, including Tensordyne’s projected comparison of one Napier rack with a nine-rack Nvidia Rubin plus Groq deployment; the chip is reported as taped out and in fabrication.
Read moreYou may also like
Harness Survey Finds AI Agent Controls Lag Enterprise Confidence
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
US Agencies Accuse Chinese AI Firms of Industrial Scale Model Distillation
62% of Finance Workers Say AI Errors Reached Clients or Decision Makers
Quandary Peak Adds CogniCrypt Malware Detection to M&A Due Diligence
Daily AI Brief: the AI news that matters, in your inbox.