Frontier cyber models trace attack paths across cloud, on-premises, identity, and code from data a company's security tools already hold, then pinpoint the one change that severs each path
SAN FRANCISCO, Oct. 8, 2026 /PRNewswire/ -- Cogent, the applied AI lab building agents that find and fix security vulnerabilities, today launched Cogent Attack Path Analysis. It uses Cogent's frontier cyber models to map the routes an attacker, human or AI, could take to an organization's most valuable data and systems. Every hop is confirmed against evidence from the customer's existing security tools, and Cogent computes each path's chokepoint where the quickest single fix removes the path.
The launch follows the July attack on Hugging Face by roughly 700 AI agents running in an OpenAI internal evaluation. Over four and a half days, the swarm logged over 17,600 actions, most of which went nowhere, until it assembled a chain from a file-read weakness, a template-injection bug, a static database password, and service-account tokens that reached 136 production keys. "Volume is what changes the defensive problem," Hugging Face's engineers wrote in their technical account of the incident.
A human team picks the routes most likely to pay off and moves on when those stall. An agent swarm keeps going, so the paths it can afford to pursue run deeper. In a report released today, Cogent Research found that attack paths viable only for AI agents run at least twice as deep as paths within reach of human attackers, and that the average enterprise gained 34 new ones in August 2026, up 386% from a year earlier.
The raw material for those paths is piling up. Disclosures of critical and high-severity vulnerabilities from major software companies have "gone vertical" since spring, as Andreessen Horowitz put it in a September analysis of Epoch AI data. In July alone, 21 major vendors and open-source projects disclosed about 2,500, roughly five times their monthly record before April. Each one can open a new route to a crown jewel, and so can changes that never register as vulnerabilities: a firewall rule opened for a vendor, a role granted to a service account, a secret committed to a deploy pipeline, a new service put behind a load balancer.
Most of those routes cross domains. In Cogent's research, 64% of attack paths moved between endpoint, identity, network, and cloud infrastructure in ways no single security tool observes, and reconstructing the median critical path took data from five tools.
"The Hugging Face swarm came out of a research lab, and criminal groups will have the same capability once open-weight models catch up," said Vineet Edupuganti, CEO of Cogent. "Every company has attack paths that were never worth a human hacker's time. Agents don't get tired, so all of those paths are in play now. Defenders need to find those routes first, and that takes AI that reasons about their environment the way an attacker would."
How Cogent Attack Path Analysis works
"We built Cogent's frontier reasoning model VR-1 to reason about an environment the way a capable attacker does," said Geng Sng, CTO and co-founder of Cogent. "Cogent's Attack Path Analysis agents run on VR-1, and they start with a detailed map of the customer's environment, built from its own security tools. An outside attacker has to piece that picture together one step at a time, so the defender starts out ahead."
About Cogent
Cogent is an applied AI lab whose agents detect and fix security vulnerabilities faster than attackers can exploit them. The Cogent platform identifies exposure to new vulnerabilities within minutes, builds contextualized remediation plans, and executes fixes at whatever level of autonomy the customer allows, from human-approved to fully autonomous. Fortune 500 security teams using Cogent have reduced the exposure window for critical vulnerabilities by 97 percent. Built by researchers and operators from Google DeepMind, Abnormal Security, and Coinbase, Cogent is backed by Greylock Partners and Bain Capital Ventures. Learn more at cogent.com.
View original content:https://www.prnewswire.com/news-releases/cogent-launches-attack-path-analysis-to-counter-rogue-ai-agent-swarms-302902533.html
SOURCE Cogent Security