安全客September 3, 2026🇨🇳Translated from Chinese

Zhou Hongyi Warns AI Tools Are Industrializing Vulnerability Discovery

At the Fourth Cyberspace Security Forum held in Tianjin on September 2, 360 founder Zhou Hongyi warned that vulnerability discovery is moving from manual craftsmanship to industrialized production. He noted that AI tools are compressing the time required to find high-value flaws from months or even years down to just a few hours, giving attackers a decisive advantage in automation capacity.

Security teams already feel the pressure. Emergency response groups are frequently awakened at 2 a.m. by newly disclosed zero-days already being exploited in the wild. Analysts must quickly assess how many assets remain exposed and whether patches can be deployed before the next business peak. The pace has accelerated so rapidly that defenders barely finish one remediation cycle before the next weaponized exploit appears on dark-web forums.

Zhou Hongyi described the change as the end of the "handicraft workshop" era. Previously, finding a critical vulnerability required senior researchers to spend months analyzing millions of lines of code and running prolonged fuzzing campaigns with uncertain results. This natural limit kept high-value zero-day output relatively manageable for defenders.

The situation has shifted with the arrival of tools such as Mythos. 360’s own Tulongfeng platform, released in June, has already identified more than 10,000 vulnerabilities, 212 of which received authoritative verification. Among them are long-undiscovered high-risk flaws in Windows and Office, as well as issues in intelligent-agent platforms including OpenClaw, Flowise, and Codex. These numbers demonstrate that vulnerability mining has achieved genuine economies of scale for the first time.

Even more concerning, Zhou Hongyi introduced the concept of the "second one-way transparency." Offensive experience once accumulated over a decade by elite red-team operators—bypass techniques, lateral-movement intuition, and internal-network tradecraft—can now be distilled into prompts, toolchains, and automated playbooks. These can be loaded into AI agents, allowing novice attackers to replicate sophisticated operations previously reserved for experts. Attack volume and depth are now limited primarily by compute resources rather than the number of skilled humans.

Intelligent agents themselves are becoming a new attack surface. Many organizations are deploying AI agents for operations, customer service, and data analysis, granting them database access, API calls, and file-system permissions. A single prompt-injection or supply-chain compromise can turn an agent into an autonomous insider that collaborates with other agents, dramatically accelerating lateral movement.

Zhou Hongyi advocated a "model-versus-model" defense strategy. 360’s Yitianzhen system uses swarms of security agents to perform continuous threat detection, validation, coordinated response, and remediation. For frontline teams, he recommended three immediate actions: automate vulnerability-intelligence workflows with SOAR platforms so humans only make final decisions; inventory and regularly audit permissions granted to every internal AI agent, including logging and kill-switch mechanisms; and begin using AI assistance for code review and detection-rule creation to close the efficiency gap with attackers.

The conclusion is direct: AI will not replace security engineers, but attackers who use AI will replace defenders who do not. Vulnerability industrialization has begun, and defensive automation must move from slideware to operational reality measured in hours rather than days.

Related articles

HabrAI Security

Do You Really Know What Your AI Agent Is Doing in the Sandbox?

The rise of agentic AI systems has exposed critical gaps in observability when agents run inside strong isolation environments. Traditional eBPF-based monitoring on the host kernel fails when agents execute under separate kernels provided by gVisor, Kata, or Firecracker. Experiments with a controlled syscall generator show that visibility depends heavily on filesystem configuration rather than the choice of runtime. Standards such as MCP, OpenTelemetry, and RuntimeClass address parts of the agent lifecycle but leave actual syscall-level reporting undefined. Measurements across multiple configurations reveal that some operations, especially execve, never reach the host regardless of the sandbox used. The findings highlight that security tooling must be re-evaluated after every change in sandbox settings.

BoletimSecAI Security

Russian State-Linked Group GTG-20006 Uses Anthropic AI Agents to Automate Malware Rebuilding

Anthropic has identified a Russian state-linked operation tracked as GTG-20006 that deployed autonomous AI agents to continuously rebuild its malware arsenal whenever detections occurred. The group, connected to Midnight Blizzard, APT29 and Cozy Bear, created a closed-loop automation system in which AI agents monitored tool performance against known defenses and triggered immediate code modifications to evade security products. Beyond malware, the agents handled domain registration, hosting infrastructure setup, phishing email delivery, command-and-control channel monitoring and implant persistence tracking across compromised environments. The campaign, active in July and August 2026 and overlapping with CaptiveCrunch, targeted more than twenty organizations including ministries, defense bodies, embassies and think tanks across Ukraine, Europe, the Middle East and Asia. In one incident the attackers exfiltrated over 300,000 national identity records and commercial registration data for more than 500,000 companies. Anthropic disrupted the activity and published a detailed report highlighting how the automation shifted the cost burden back onto defenders.

安全客AI Security

Anthropic Exposes Widespread Weaponization of Claude by Nation-State Hackers and Cybercriminals for Automated Attacks

Anthropic has released a threat intelligence report detailing how multiple state-sponsored and criminal groups systematically abused its Claude model between December 2025 and August 2026. The company introduced the term Generative Threat Groups to describe actors that built multi-agent frameworks to automate reconnaissance, exploitation, and data exfiltration. One group identified as GTG-20006, widely linked to Midnight Blizzard, APT29 and Cozy Bear, created an AI-driven workflow that automatically rewrites and redeploys malware once security tools detect it. The report highlights that this capability collapses the traditional gap between well-resourced nation-state operations and individual attackers. Defensive recommendations focus on shifting detection to behavioral chains, shortening IOC validity periods, strengthening data-loss prevention, and establishing internal governance for AI tool usage.

安全客AI Security

Unit 42 Details First Multi-Agent AI Ransomware Attack That Finished in Ten Hours

Palo Alto Networks Unit 42 has published the first confirmed case of a multi-agent AI ransomware operation. Attackers only defined the target; more than ten specialized AI agents then performed reconnaissance, credential harvesting, lateral movement, data exfiltration, and encryption within ten hours. The agents used over fifty ATT&CK techniques and successfully hid command traffic inside the victim’s own AI service endpoints. After encryption the same agents automatically generated an eighty-page security audit report listing every compromised system and technique. The sole defensive control that stopped part of the attack was a mandatory multi-person code review rule on Terraform changes. Unit 42 links the operation to frontier large-language-model frameworks and notes that earlier single-agent incidents such as JADEPUFFER have now evolved into coordinated agent fleets.