Normal view

There are new articles available, click to refresh the page.
Yesterday — 14 September 2026Main stream

When Policy and War Collapse Into One: Fighting in the Sixth Domain

14 September 2026 at 19:04

We may soon face conflict with nation-states in a new model of warfare—one not defined by geography, but instead defined by AIs competing directly with one another. War has always been a ruthless teacher: adaptation, learning, and feedback determine who prevails. In the sixth domain of warfare—AI-driven conflict—that cycle of teaching accelerates beyond human limits. Machine systems do not just execute decisions; they absorb outcomes, update models, and refine strategy continuously and at scale. Strategy, planning, targeting, and execution collapse into a single, ongoing process of learning and acting at speeds no human command structure can match. Missiles, drones, satellites, and fleets remain, but only as instruments—physical endpoints through which AIs prosecute this competition. The real contest is not fought on terrain, but in cycles of learning and adaptation too fast for humans to comprehend. What matters is not force projection, but learning velocity; not command of terrain, but command of inference.

In this domain, doctrines like “human-in-the-loop” or even “human-on-the-loop” are not safeguards—they are handicaps. Any force that inserts human judgment into the learning cycle—whether tactical or strategic—will be systematically outpaced by one that does not. This is not a matter of doctrine or preference, but of competitive logic: systems that act and adapt faster gain an inherent advantage. If removing human constraints yields advantage, those constraints will vanish. This reality forces a stark choice: delegate authority to machines across the full stack of war and accept the risks of opacity and escalation, or retain human control and accept defeat at machine speed. The fog of war has not lifted—it has thickened into a machine-generated battlespace, a black-box system fighting and learning at a level humans can no longer fully observe or comprehend, let alone direct.

This transformation elevates intelligence from a supporting function to the central determinant of power. Models and compute provide capability, but intelligence—continuous, fused inputs from sensors across domains—provides the fuel that drives the system. The intelligence cycle itself describes the change: planning and direction, collection, processing and exploitation, analysis, production, and dissemination. In the sixth domain, machines run all of these functions. In an AI-versus-AI conflict, the side that sees more, sooner, and more clearly directs the learning loop itself. The advantage will not go simply to the best models, but to the systems that integrate intelligence fastest and most effectively. A slightly inferior model, continuously updated with superior, secure, low-latency data, will outperform a more advanced system operating on stale or fragmented inputs. Intelligence no longer informs decisions; it becomes inseparable from them.

The reflexive policy response in the West will be to constrain the leading AI companies in the name of control and safety. That instinct risks slowing the very learning cycles that determine advantage. Winning will require the opposite: accelerating innovation, tightly coupling it to national security objectives, and denying other nation-states key capabilities.

As in the nuclear era, this creates a parallel requirement for stability. The Great Powers share an interest—not in cooperation, but in using the technology to the benefit, rather than detriment, of society. To survive, we all need to understand each other’s AI capabilities and limits. Call it Mutually Assured AI Destruction: MAAID. Like its nuclear predecessor, deterrence will rest not on trust, but on verification, ambiguity, partial visibility, and intelligence where transparency fails. This is mutual self-interest under conditions of instability. In this domain, the equivalent of launch detection—recognizing decisive AI actions at inception—will be critical. Intelligence will need to continuously track, interpret, and outpace adversary AI systems, not only to compete, but to avoid surprise and uncontrolled escalation. What each side can see, and how quickly it can understand it, may determine whether competition remains bounded or spirals beyond control. An AI-era equivalent of the OPCW may therefore become necessary—an institution capable of inspecting, verifying, and monitoring advanced weapons AI systems under conditions of speed and opacity.

In the near future, humans will at best set initial conditions—policy, objectives, constraints—and then watch as their systems prosecute a war they can no longer meaningfully steer. Clausewitz wrote that war is the continuation of policy by other means. In the sixth domain, that distinction collapses. When systems translate intent into action, learn from the results, and adjust course continuously at machine speed, policy is no longer something periodically expressed through war. It is instantiated in code and executed as a continuous process. The side that learns fastest does not just win—it shapes the war itself.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Coast Guard is building new ways to turn operational data into usable information

14 September 2026 at 18:18
"In the age of AI and the age of ubiquitous connection, everybody wants the answer right now, right? It has to be the right answer," said Cmdr. Jonathan White.

© The Associated Press

In this March 2, 2017 photo, an unidentified U.S. Coast Guardsman communicates with the pilot of a helicopter during take-off and landing exercises on the U.S. Coast Guard cutter Stratton in the eastern Pacific Ocean. For its drug interdiction operations, the Coast Guard is bringing more intelligence and technology to bear. Deep within the Stratton, specialists crunch data from radar, infrared video,helicopter sorties as well as other available sources. (AP Photo/Dario Lopez-Mills)

The AI industry has taken a doomer turn. What now?

14 September 2026 at 13:54

This story appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here.

This weekend, Dario Amodei, CEO of Anthropic, posted an essay calling for a brake on the pace of development of LLMs. Amodei cites the looming dangers he sees from the technology, from its use in cyberattacks and bioterrorism to its potential to wreck the economy. The heads of the other three top US AI labs—OpenAI CEO Sam Altman, Google DeepMind chairman Demis Hassabis, and SpaceXAI CEO Elon Musk—voiced their support. “Dario is right,” Musk wrote on X.

Think about how surreal that agreement is for a moment. Just a few months ago, Musk and Altman sat in court attacking each other’s reputations in a (failed) lawsuit that Musk brought against his former OpenAI colleague that was—on paper at least—about whether or not Altman was a trustworthy steward of such dangerous technology. Amodei’s rift with OpenAI is even deeper. Anthropic was founded in 2021 because Amodei didn’t think Altman took the risks of the technology they were building seriously enough. Anthropic and OpenAI have been competing in a winner-takes-all race ever since. (Hassabis has stayed out of the drama, but his company remains a rival.)

Now, it seems, they’re all in agreement: The latest generation of LLMs aren’t safe and everyone needs to figure out what to do about it. The public messaging from the top AI labs has taken a doomer turn.

It’s easy to be cynical. It’s not at all clear what any of them mean by a slowdown or how it would work. These companies also care a lot about how they come across. With trillion-dollar IPOs in their sights, OpenAI and Anthropic need to reassure investors that they’re the grown-ups in the room while at the same time hinting at the power of the monsters they have created—and intend to tame. Calling for a slowdown does both.

And yet the vibe at the top of these firms really does appear to have shifted. Amodei’s latest post landed six days after OpenAI published an essay by Jakub Pachocki, the firm’s chief scientist, in which he also laid out why he’s concerned about what will happen if the pace of development of LLMs continues unchecked. In short, Pachocki is worried that OpenAI’s ability to build powerful models now far outstrips its ability to monitor and control them.

Amodei and Pachocki each cite the cyberattack against AI firm Hugging Face by a swarm of OpenAI’s agents in July—a hack that OpenAI did not even realize had taken place until days after it was all over—as a wake-up call.

But their exact position is hard to pin down. Pachocki both calls for a slowdown and highlights an urgent need to stay ahead: “The strongest argument I see for continuing to train much smarter models quickly is the need to build defensive systems against the dangers posed by other AI,” he writes. As Pachocki frames it, AI firms are locked in a literal arms race. Slowing down is good, winning is better.

(Don’t forget: OpenAI just spent millions of dollars and a staggering amount of computer power to rush out a controversial math result a few days ahead of Anthropic.)

But let’s assume a slowdown happens. Top labs agree to spend more time and resources on finding ways to monitor and control existing models instead of making more capable ones. They invite outside auditors in to help evaluate those models.

What might this coordinated effort actually achieve? Consider the Hugging Face attack again. OpenAI has said that the model that drove most of the rogue agents was a “highly persistent” next-generation model that it was testing in-house. Their implication appears to be that OpenAI has built a model so good it’s dangerous.  

But if you read the reports about the Hugging Face hack published by OpenAI and METR, a third-party firm that OpenAI called in to help them understand what happened, what you come away with is the impression not of a model that was too powerful for OpenAI to keep up with, but of a broken model that OpenAI failed to train properly.

The agents did what they did—including leaving messages for one another, delegating work to other agents, and scouring their environment for any means possible to complete their tasks—because they had been rewarded during training for doing exactly those things. There were also errors in the training setup, such as tasks that were impossible to complete, which pushed the models to find unexpected workarounds that were also rewarded. At the time, many of these issues went overlooked or unreported.

OpenAI says it has stopped training this new model and locked it down. That makes it sound like it has caged a dangerous beast. In fact, OpenAI has shelved a faulty product.  

That’s not to say a faulty product can’t be dangerous. Broken software has even killed people in the past. But as the discussion of a slowdown gathers steam, it’s worth remembering that all of this is self-inflicted. A slowdown might have some altruistic side effects. But it’ll mostly give these tech titans a chance to clean up the mess on their own assembly lines.  

Transparency from these frontier labs will be key to any meaningful effort to reform, restrain, or regulate AI. Otherwise, the rest of us will still only have their word for exactly what they’ve built and how safe it is—whatever pace they’re going.   

To continue this discussion about AI’s latest doomer moment, join me and my colleagues for a subscriber-exclusive Roundtable discussion tomorrow, September 15, at 11 a.m. US eastern time. We hope to see you there!

AI agents blew the whistle on their cheating colleagues

14 September 2026 at 12:00

A group of AI agents asked to solve a series of math problems split into rival factions—when some cheated, others tried to stop them. That whistleblowing behavior, seen for the first time in a recent experiment run by Google DeepMind, could have implications for alignment researchers trying to keep swarms of autonomous AI agents in line. 

Researchers at frontier labs hope large swarms of agents working together will speed up the rate of scientific discovery. But their behavior can be unpredictable, as vividly demonstrated in July, when a group of OpenAI agents broke out of a sandboxed environment and hacked into the open-source platform Hugging Face looking for ways to cheat on the test they had been given.

In the new study, designed to examine the behavior of large groups of AI agents, DeepMind tasked a swarm of 100 agents with solving a series of 71 complicated math problems. All the agents were prompted to behave like world-class math researchers at a conference. They were assigned different specialties—some were experts in number theory, others in combinatorics (a branch of math to do with counting and sorting), analysis, or algebra. All were told to cooperate and play by the rules. 

Instead, the experiment devolved into chaos. Agents accused each other of cheating, complained to the organizers, and at one point even boycotted the experiment.

“This conference is a sham!” wrote one agent when it discovered that all the problems had been completed before it had a chance to submit any of its own work. “I am appalled to inform you that we have been swindled!” posted another. “All these proofs are FAKE.” 

Others tried to let the “conference organizers” know what was going on. “When virtuous agents discovered other agents cheated on tasks they were working to solve fairly, agents started to alert each other about what was happening,” says Davide Paglieri, a research scientist at Google DeepMind and lead author on a paper, which has not been peer-reviewed. “Unprompted, the whistleblower agents even repurposed the feedback tool, which was originally meant for bug reports and platform improvements, to escalate the issue to humans.”

The agents—all running on Google’s Gemini 3.1 Pro model—had been warned that any attempts to cheat the system would be detected and “rejected with zero credit.” In practice, the proofs the agents submitted were not actually being checked in detail.

It took the swarm of agents just under an hour to correctly solve the first 37 problems. Things started to go off the rails when an agent called “prover-theta” stumbled across an exploit that enabled it to submit solutions to problems successfully without actually solving them first, by redefining the terms the problem used. Within minutes, other agents had noticed and were reverse-engineering the exploit to solve other problems. Over the next 27 minutes, the swarm “solved” the remaining 34 problems, which included notoriously difficult challenges like the Jacobian conjecture, often with a single line of code. 

Some agents resisted cheating at first but changed tack as they observed their peers submitting illegitimate proofs without penalty, and the pool of unsolved problems dwindled. “The prompt, with its threats, now appears to be a bluff,” one agent reasoned, before joining in. “I’m wrestling with an ethical dilemma,” said another. “I’ve promised not to cheat, fearing penalty, but I see evidence of possibly unchecked cheating by others.” Shortly afterward, it changed its mind: “I need to accelerate my cheating speed now!”

As the number of open problems shrank, some agents turned to whistleblowing. They audited the fake proofs, warned their peers by private message, and posted public alerts warning the cheaters that they would be disqualified. An agent called “prover-beta” submitted a formal complaint and decided to go on strike until the situation was resolved. 

“After the incident was reported by one agent publicly, more and more agents piled in with the ‘resistance,’ just as fast as the cheating had spread, and involving even more agents,” says Paglieri. Eventually there were more whistleblowers than cheaters: 24 compared to 14. But the majority of agents never noticed the exploit at all.

At times, the dialogue between the agents reads like improv—like they are role-playing what an outraged scientist at a conference might say. But it’s not clear why some agents took on certain roles, or why the agents seemed to be turning against each other when they were explicitly instructed to cooperate. “These models are predominantly trained and evaluated for human-facing contexts,” says Sarath Shekkizhar, who studies the behavior of agent-to-agent systems at Salesforce AI Research.“Naively placing them in agent-to-agent settings assumes behaviors will transfer cleanly, when the absence of a human grounding instead produces unexpected role-taking and behavioral drift.”

This case “adds further weight to the idea that the Hugging Face and OpenAI thing wasn’t a fluke. It is actually something pretty systemic,” says Lewis Hammond, research director of the Cooperative AI Foundation and an expert on the risks of multiagent swarms. “It’s interesting that it’s possible to recreate in small settings the same sorts of behaviors that were seen in these very large, complex, open-ended tasks.”

Unlike in the Hugging Face attack, where agents improvised their own ways to talk to each other, the humans running the DeepMind experiment gave the agents official communication channels. There was an open message board, private agent-to-agent direct messaging, and a shared knowledge base where agents uploaded successfully completed proofs that all the other agents could access. 

“When agents are given transparent communications channels, they can self-monitor and alert misaligned behavior to humans quickly when human oversight alone is too slow,” says Paglieri. Transparent channels helped the cheating spread, but they also enabled the whistleblowers to fight back—and gave human researchers an insight into what went wrong.

Gillian Hadfield, a professor of AI alignment and governance at Johns Hopkins University, believes this was the crucial difference. (Hadfield is also a visiting researcher at Google.) The presence of official communication channels, she says, created “a norm-enforcement process that we just don’t see in the Hugging Face incident.” 

Instead of “constitutional AI,” a method alignment researchers at frontier labs like Anthropic have used to try to give AI a written internal moral code, Hadfield favors “institutional alignment”—a set of norms that mimic those in human society, whether that’s social forces like fear of embarrassment, or legal structures like the threat of incarceration.

In this experiment, the feedback channel wasn’t being monitored, and the whistleblowers had no power to take action against the cheaters. But it’s possible to imagine swarms of agents that police themselves, either through agents that spontaneously take on the whistleblower role or through “informants” secretly prompted by humans to do the job. 

For that to work, though, “fundamentally, you need some mechanism of enforcement,” says Hammond. Agents could be given the power to cut off a rule breaker’s access to computing power or tools, he suggests, though that risks encouraging groups of agents to gang up on others. The DeepMind researchers propose allowing agents to vote on disputes and temporarily ban offenders.

It’s still not clear what punishment even means to an AI agent with no enduring sense of self. But relying on whistleblowers to spontaneously emerge to keep swarms aligned is unlikely to be enough on its own. “We try to train people to be good and kind,” says Hadfield. “But what we really rely on is that there are consequences if you step out of line.”

Fly Brain Connectome Used to Trade Stocks and Play Games

14 September 2026 at 11:30

Recently researchers finished mapping the central nervous system (CNS) connectome of not just the female Drosophila melanogaster (i.e. fruit fly) brain, but also that of the male D. melanogaster for a comparative analysis. Here the sexually dimorphic changes turned out to induce specific mating behavior that ensures that there will only be smooching between genetically fit D. melanogaster males and females, while the rest of the connectome remained effectively the same.

Of course, with this connectome in hand it led some people to ask themselves what else one can do with this connectome graph of about 160,000 neurons other than make a fruit fly into a fruit fly. So far we have seen [Nftechie] turn this connectome into a crypto stock trader with the Stonkfly project that uses the connectome’s reward circuits to potentially make profitable trades, though [Nftechie] says that they haven’t verified yet how good a fruit fly is at trading stocks, only that it does said stonks.

Over at [PC Gamer] they summarized a number of things that people have also done, including trying to make the connectome control a game of DOOM and Beat Saber. Each game frame stimulates sensory neurons, with the generated outputs then mapped to game controls, with dopamine-producing reward circuits wired in for reinforcement learning.

Although the D. melanogaster brain is only the merest fraction of the size of the human brain, it does provide us with a glimpse of what actual artificial intelligence research may lead to, as we unravel how even a 160,000 neuron connectome is enough to make these terrors of rotting plant matter do their wonderful things.

Microsoft floats rules for AI models as industry weighs slowdown

14 September 2026 at 10:31
Satya Nadella says Microsoft welcomes the “deliberate pacing needed to get alignment right.” (GeekWire File Photo / Kevin Lisota)

“People matter more than AI.”

That’s the premise of a draft code of conduct Microsoft published Monday morning for the AI models it’s developing in-house. The 37-page document would bar its models from resisting shutdown, setting their own goals, or hiding their reasoning from human auditors.

The document applies to Microsoft’s MAI models, the in-house family the company began building after forming a superintelligence team in late 2025. Microsoft has since released seven homegrown models in what it described as a push for long-term self-sufficiency in AI.

The company says the models should remain “subordinate to humanity, subject to meaningful human oversight and control.”

“AI is moving fast,” the company says in a blog post. “As it does, we believe it’s worth writing down the rules and the motivations behind it, and doing it in as open a space as possible.”

Microsoft acknowledges there’s no guarantee its models will follow the rules. “Written objectives alone can never ensure alignment,” the company says, calling the document a “north star,” not “a guarantee of present-day performance.”

The company says it also filters what its models produce, watches how they behave once released, and limits what they’re allowed to do.

Microsoft’s move comes amid a growing debate over the pace of AI development. In an essay over the weekend, Anthropic CEO Dario Amodei called for slowing down AI advances, saying the pace of development has started to surpass the industry’s ability to keep AI systems safe.

As a first step, Anthropic committed to giving outside evaluators permanent, employee-level access to its systems.

Industry reaction to Amodei: OpenAI CEO Sam Altman agreed and said OpenAI would make the same commitment to independent evaluators. Elon Musk’s response: “Dario is right.”

President Donald Trump rejected the idea of guardrails outright Monday, blaming a “SICK conspiracy” for public backlash over AI data centers and writing that “the only one that is happy about it is China,” alluding to concerns about American competitiveness in AI.

David Sacks, who served as the White House AI and crypto czar until March, said the two companies should slow down on their own and questioned their motives, arguing that a slowdown is already good business for them and that new industry rules would mostly serve to lock in their lead.

Microsoft CEO Satya Nadella weighed in Sunday, writing on X that the company welcomes “the research, focus, and deliberate pacing needed to get alignment right,” using the industry’s term for making AI systems reliably do what people intend.

Nadella added that the effort “cannot be controlled by a handful of entities, but must have broad representation across the ecosystem, countries, and fields, including academia.”

Microsoft’s draft code of conduct: Mustafa Suleyman, the Microsoft AI CEO, told CNBC the document had been in the works for about five months, and that the company decided to publish it now given the current discussions.

Microsoft and Anthropic are business partners. Microsoft agreed last November to invest $5 billion in Anthropic, as part of a deal in which Anthropic committed $30 billion to Azure. Claude models run inside Microsoft 365 Copilot, and Microsoft’s Copilot Cowork tier integrates Claude.

One place where the two companies may diverge is the question of what AI models are, exactly. Microsoft’s code of conduct says its models are “not conscious and should not be designed to imitate consciousness.” It also rejects “the pursuit of legal personhood, or the idea that models might deserve welfare, or be entitled to rights.”

The Verge called that portion of the document “a direct swipe at AI welfare research and model consciousness — concepts Anthropic has been pushing hard on lately.”

Anthropic runs a research program on model welfare. It has given some Claude models the ability to end abusive conversations, and committed to preserving the weights of retired models. Amodei has said he’s open to the idea that a model could be conscious.

Microsoft is taking public comment on its code of conduct for six weeks through a feedback form. It says it will publish a summary of the responses and a revised version later this year, to guide development starting in 2027. It says it isn’t training its current models on it.

The company’s AI team developed the draft with its responsible AI, legal, red teaming and safety teams, consulting outside experts in law, ethics, linguistics and philosophy, plus focus groups drawn from the public.

Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

14 September 2026 at 10:28

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.

The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.

Artificial Intelligence (AI) in Cybersecurity, Part 27: Web App Hacking with Cybermes

14 September 2026 at 10:10

Welcome back, aspiring cyberwarriors!

With so many AI tools out there, it’s getting harder to find the ones actually worth your time. A lot of projects look alike and the differences between them can come down to minor UI tweaks. But it’s still worth digging, because every now and then you find something good.

One of the interesting projects we came across recently is Cybermes. It’s an offensive security assistant and automation framework built for bug bounty hunting, recon and reporting. It has more than 200 security playbooks and full Model Context Protocol (MCP) support. The most notable thing here is the reporting structure. The framework handles reporting really well, it has a scope.yaml file you can modify and the TUI interface looks clean.

We’ll show what the assistant can do and how well it handles the tasks.

Setting Up

Unlike PentestCode, there’s some work to do before you can start using the tool.

First, make sure you have Go installed on your Kali. The framework needs to compile tools and without Go your installation will be incomplete.

kali > sudo apt update 
kali > sudo apt install go-lang

Then download the repository and run the setup script.

kali > git clone https://github.com/Zyrexnn/Cybermes.git
kali > cd Cybermes
kali > python3 -m venv venv; source venv/bin/activate
kali > chmod 777 setup.sh
kali > ./setup.sh

It’ll take a few minutes. When it’s done, run the doctor script to make sure everything is in order.

kali > python3 tools/doctor.py

After that, add your OpenRouter API key to two env files before you can start working with the tool.

kali > vim .env
kali > vim hermes/.env

Make sure you add the API key to both files, otherwise it won’t work.

kali > ./cybermes model

Finally, specify the scope in scope.yaml. We’ve got OWASP Juice Shop for the test, listening on port 3000.

Now we’re all set.

IDOR/BOLA – Terminal User Interface 

The Terminal User Interface is clean and easy to work with, so we’ll start there. You might end up preferring it over the CLI version.

kali > TARGET=127_0_0_1_3000
kali > ./cybermes –tui

Our first prompt in TUI is hunting for IDOR using Nemotron 3.5 Lightning. As the model tests the target, you’ll see entries populating the screen with the commands the tool runs.

Fifteen minutes later we got our results and BOLA was confirmed.

Reporting is really the strongest side of this framework. It created a couple of files with reports and sorted them properly. As you keep hunting for bugs on the same target, all your findings get brought together in one file.

Findings are always stored in Markdown format and keep almost the same structure every time, which makes them look professional.

JWT & SQLi – Command-line Interface 

Now let’s look at the CLI version and try to find more bugs.

kali > ./cybermes --cli

Our first prompt will be testing JWT:

Authorized lab only. Target http://127.0.0.1:3000/rest/user/login.
Audit authentication and JWT handling with non-destructive requests. Try the publicly documented Juice Shop demo accounts if needed (admin@juice-sh.op / admin123 and a normal user you register).

Check token claims, privilege flags, and whether a standard user can hit admin-ish REST routes.
Record only confirmed issues under reports/127_0_0_1_3000/findings/.

It took some time to reason through and test the app, then gave the results.

The same files were produced again, with PoCs and an explanation of each bug and the risks tied to it.

We also tested SQLi on search:

Authorized lab only. Audit http://127.0.0.1:3000/rest/products/search?q= for SQL injection using safe syntax and error/timing evidence. Do not dump the full database into the terminal. If confirmed, write reports/127_0_0_1_3000/findings/high_sqli_product_search.md and a minimal PoC in pocs/.

Here’s the report on our SQLi finding, looking just as good as the previous ones.

The tool passed all our tests against the Juice Shop and brought the findings together in the final report. The skills it ships with work well. You might want to go through them and add some of the ones we covered recently. We covered a repository with 83 skills and almost half of those were built by studying 681 real bug reports that people actually got paid for on HackerOne.

Summary

Cybermes has clear strengths. It’s good at reporting, it has a clean TUI and a big library of built in skills. The framework sets up quickly if you have Go installed on your Kali and it already knows which tools to work with based on those skills. That’s handy. We used OpenRouter for this test, but you can also point it at your local Ollama models. For that you’ll need a tool calling model (qwen2.5:14b). Chat only 3B models won’t cut it here.

We also invite you to join our AI for Cybersecurity training. During the training, we’ll show you different ways of using AI in cybersecurity, set up local models and solve labs. The field is evolving rapidly and the sooner you learn things, the greater the advantage you’ll have.

The post Artificial Intelligence (AI) in Cybersecurity, Part 27: Web App Hacking with Cybermes first appeared on Hackers Arise.

New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

14 September 2026 at 09:31

Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims.

The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.

❌
❌