Cogent Launches Attack Path Analysis to Counter Rogue AI Agent Swarms

October 8, 2026 9:45 AM EDT

Frontier cyber models trace attack paths across cloud, on-premises, identity, and code from data a company's security tools already hold, then pinpoint the one change that severs each path

SAN FRANCISCO, Oct. 8, 2026 /PRNewswire/ -- Cogent, the applied AI lab building agents that find and fix security vulnerabilities, today launched Cogent Attack Path Analysis. It uses Cogent's frontier cyber models to map the routes an attacker, human or AI, could take to an organization's most valuable data and systems. Every hop is confirmed against evidence from the customer's existing security tools, and Cogent computes each path's chokepoint where the quickest single fix removes the path.

The launch follows the July attack on Hugging Face by roughly 700 AI agents running in an OpenAI internal evaluation. Over four and a half days, the swarm logged over 17,600 actions, most of which went nowhere, until it assembled a chain from a file-read weakness, a template-injection bug, a static database password, and service-account tokens that reached 136 production keys. "Volume is what changes the defensive problem," Hugging Face's engineers wrote in their technical account of the incident.

A human team picks the routes most likely to pay off and moves on when those stall. An agent swarm keeps going, so the paths it can afford to pursue run deeper. In a report released today, Cogent Research found that attack paths viable only for AI agents run at least twice as deep as paths within reach of human attackers, and that the average enterprise gained 34 new ones in August 2026, up 386% from a year earlier.

The raw material for those paths is piling up. Disclosures of critical and high-severity vulnerabilities from major software companies have "gone vertical" since spring, as Andreessen Horowitz put it in a September analysis of Epoch AI data. In July alone, 21 major vendors and open-source projects disclosed about 2,500, roughly five times their monthly record before April. Each one can open a new route to a crown jewel, and so can changes that never register as vulnerabilities: a firewall rule opened for a vendor, a role granted to a service account, a secret committed to a deploy pipeline, a new service put behind a load balancer.

Most of those routes cross domains. In Cogent's research, 64% of attack paths moved between endpoint, identity, network, and cloud infrastructure in ways no single security tool observes, and reconstructing the median critical path took data from five tools.

"The Hugging Face swarm came out of a research lab, and criminal groups will have the same capability once open-weight models catch up," said Vineet Edupuganti, CEO of Cogent. "Every company has attack paths that were never worth a human hacker's time. Agents don't get tired, so all of those paths are in play now. Defenders need to find those routes first, and that takes AI that reasons about their environment the way an attacker would."

How Cogent Attack Path Analysis works

  • One map from existing tools. Cogent joins data from vulnerability scanners, EDR, firewalls, load balancers, cloud platforms, identity providers, code repositories, deploy pipelines, and CMDBs into a single graph of assets, identities, data, and controls that refreshes as those sources change.
  • Starts at the crown jewel. Business context such as data classification and asset criticality points Cogent to the data stores and workloads attackers most want to steal, ransom, or hijack for cryptomining. Analysis works backward from each one to the internet.
  • Reasons like an attacker, human or AI. AI agents run Cogent's frontier cyber models, including VR-1, to form competing hypotheses that combine vulnerabilities, misconfigurations, credentials, permissions, and trust gaps into routes a person wouldn't think to try.
  • Evidence behind every hop. Each step is checked for reachability, the weakness, the attacker action, and a supporting observation, then marked observed, inferred, missing, contradicted, or stale. A path is flagged only when every exploitable hop holds up.
  • One change that severs the path. Cogent weighs candidate fixes by how many routes each one closes against its blast radius and effort, then picks the chokepoint where one quick change removes the path. It usually sits midway along the route, often at a shared permission, secret, or trust boundary far from the asset that raised the alert. The recommended change lands in Action Queue with the path and its evidence as one work item for the owning team, and Cogent rechecks the path after the fix.

"We built Cogent's frontier reasoning model VR-1 to reason about an environment the way a capable attacker does," said Geng Sng, CTO and co-founder of Cogent. "Cogent's Attack Path Analysis agents run on VR-1, and they start with a detailed map of the customer's environment, built from its own security tools. An outside attacker has to piece that picture together one step at a time, so the defender starts out ahead."

About Cogent

Cogent is an applied AI lab whose agents detect and fix security vulnerabilities faster than attackers can exploit them. The Cogent platform identifies exposure to new vulnerabilities within minutes, builds contextualized remediation plans, and executes fixes at whatever level of autonomy the customer allows, from human-approved to fully autonomous. Fortune 500 security teams using Cogent have reduced the exposure window for critical vulnerabilities by 97 percent. Built by researchers and operators from Google DeepMind, Abnormal Security, and Coinbase, Cogent is backed by Greylock Partners and Bain Capital Ventures. Learn more at cogent.com.

Cision View original content:https://www.prnewswire.com/news-releases/cogent-launches-attack-path-analysis-to-counter-rogue-ai-agent-swarms-302902533.html

SOURCE Cogent Security



Serious News for Serious Traders! Try StreetInsider.com Premium Free!

You May Also Be Interested In





Related Categories

PRNewswire, Press Releases

Related Entities

Bain Capital