Loading video...

Video Failed to Load

Go Home

THIS IS F**KING DANGEROUS FOUND AN AI RED TEAM THAT NEEDS ZERO HUMAN INPUT PentAGI. Scanner —> Exploiter —> Reporter —> three agents, working as a swarm, sharing results in real time. One does recon, another finds and runs the actual exploits, a third writes the professional vulnerability report...

36,837 views • 16 days ago •via X (Twitter)

54 Comments

MAX's profile picture
MAX16 days ago

Repo: Follow @maxdeg0 for more

Karan Kaushal's profile picture
Karan Kaushal14 days ago

with 22k stars still can't beat Xalgorix

Hydareth乍得's profile picture
Hydareth乍得16 days ago

wild time for cybersecurity

MAX's profile picture
MAX16 days ago

For real. Cybersecurity is entering a completely different era.

Butch Coolidge's profile picture
Butch Coolidge15 days ago

Pentagi sucks. Use xalgorix instead thx me later

Alex13's profile picture
Alex1316 days ago

yeah this is the moment pentesting stopped being a slow human grind and turned into machines hunting machines while we just watch the reports roll in

MAX's profile picture
MAX16 days ago

the shift to autonomous security testing is happening much faster than I expected.

Davidd Tech's profile picture
Davidd Tech16 days ago

Did you see what happened with OpenAI Hugging Face?

MAX's profile picture
MAX16 days ago

Yeah, that whole OpenAI × Hugging Face situation was wild.

Blackfrost_AI's profile picture
Blackfrost_AI16 days ago

Now, when you combine this with one of our frontier models that have been professionally de-risked. The engagement then turns very one-sided.

Polykinder's profile picture
Polykinder16 days ago

AI capabilities are surprising

MAX's profile picture
MAX16 days ago

Honestly, the pace of AI capabilities is surprising. Things are moving fast.

MAX's profile picture
MAX16 days ago

Proceed with caution lol 😆

EugBass's profile picture
EugBass16 days ago

;)

MAXI (❖,❖)'s profile picture
MAXI (❖,❖)16 days ago

How efficient is it

MAX's profile picture
MAX16 days ago

Pretty efficient for recon and finding common vulnerabilities but human validation still needed some times

hammertime's profile picture
hammertime16 days ago

AI vs AI cybersecurity is getting scary

MAX's profile picture
MAX16 days ago

AI vs AI in cybersecurity is becoming a very real arms race.

Wayne's profile picture
Wayne16 days ago

scary asf

MAX's profile picture
MAX16 days ago

Haha Don’t be 😆

Yakubu David block's profile picture
Yakubu David block16 days ago

This is gold bro thanks

kadd's profile picture
kadd16 days ago

Thanks for sharing man

MAX's profile picture
MAX16 days ago

Always bro, glad you found it useful.

Lynor ⛓️'s profile picture
Lynor ⛓️16 days ago

autonomous recon to reporting in one workflow is kinda wild

MAX's profile picture
MAX16 days ago

Yeah, going from recon to a finished report in one workflow is pretty wild.

Lynor ⛓️'s profile picture
Lynor ⛓️16 days ago

the automation across every stage is the interesting part

X's profile picture
X16 days ago

It drops the cost but still most insurance companies will require some type of certified (human) Pen test, especially for anything involving heavy PII or PCI-DSS (monetary transactions).

MAX's profile picture
MAX16 days ago

Exactly. AI can cut costs massively, but human certified testing is still important for compliance.

Аnnetta's profile picture
Аnnetta16 days ago

Is it safe to rely entirely on AI without human control?

厨二病エンジニア's profile picture
厨二病エンジニア16 days ago

人間の手が入らないまま脆弱性まで自動で突かれるなら、デバッグが終わる前にバグの方が先に育ち切る未来しか見えない。

Oxlee 🐬's profile picture
Oxlee 🐬16 days ago

That sounds like the future of autonomous hacking teams

MAX's profile picture
MAX16 days ago

autonomous hacking teams are definitely starting to look like the future.

starmex's profile picture
starmex16 days ago

zero human input is where this starts getting a little scary lol

MAX's profile picture
MAX16 days ago

that’s the part that makes it both impressive and concerning.

VANTERRA's profile picture
VANTERRA16 days ago

Max bro Thanks for sharing

emelu's profile picture
emelu16 days ago

mamma mia 🥺 max gibbin me dangerous alphas

MAX's profile picture
MAX16 days ago

haha Just doing my part, bro. More alpha on the way.

Alex Stone's profile picture
Alex Stone16 days ago

Multi-agent autonomy gets powerful fast once agents can hand work off without human coordination.

MAX's profile picture
MAX16 days ago

Exactly autonomous handoffs make multi agent systems much more powerful.

MAIL's profile picture
MAIL16 days ago

very useful resource

MAX's profile picture
MAX16 days ago

Yeah, this is definitely one worth keeping around

Bober_smart's profile picture
Bober_smart16 days ago

Dude, that's a real alpha move, I'm going to try doing that right now

MAX's profile picture
MAX16 days ago

Go for it bro, once you get it set up you’ll see why it’s so good.

Stuey's profile picture
Stuey16 days ago

That’s for all your posts mate, I was actually looking at this same project yesterday. Have you used it yet, if not what’s your goto?

MAX's profile picture
MAX16 days ago

I’ve used it before. And it efficient

🌎 Coin Hub - Go Global 🌎's profile picture
🌎 Coin Hub - Go Global 🌎11 days ago

Let’s talk⚡️dm us

Crypto Mavka's profile picture
Crypto Mavka16 days ago

I notice so many new things on Twitter that I can't stop following them all.

MAX's profile picture
MAX16 days ago

For real, the amount of new stuff dropping every day is crazy. Hard to keep up.

painn's profile picture
painn16 days ago

this is crazy, thanks for sharing

MAX's profile picture
MAX16 days ago

the pace of this stuff is honestly crazy. Glad you found it useful.

Akhil Sharma 🧠 System Design's profile picture
Akhil Sharma 🧠 System Design16 days ago

Check this out, takes the idea to a different level -

Anonrob1821's profile picture
Anonrob182110 days ago

Wild times are on the raise 😎

riVeN's profile picture
riVeN16 days ago

recon can be autonomous. the moment it runs exploits, the missing node is the one that checks authorization.

Eric's profile picture
Eric16 days ago

Don't big models like Claude and codex refuse to work on tasks like this ?

Related Videos

elon musk started with 7 grok agents. by morning each had spawned somewhere between 80 and 900 more on its own, and no one had told them to multiply. openai and anthropic each sell you one agent that sits still for $400. this whole self-building swarm runs for $5 the swarm above is that overnight run, seven seeds that turned into thousands, every one of them working a slice of the same job with nobody at the keyboard here is the exact setup, and it costs nothing on top of a $5 key: -> spin up one grok agent and give it a standing order instead of a prompt: own a boring niche people search every day -> it reads x and reddit complaints in real time and picks the one nobody wants but everybody googles, because it is grok and it sees the whole app -> when the work outgrows it, it spawns its own helpers, 80 to 900 of them, and splits the site between them -> they build it on their own machines and ship 3 to 6 useful pages a night, on a routine you set once -> the swarm writes, negotiates and closes its own affiliate and referral deals by email, in your name, at 3am -> telegram sends you the money report and you never open the site -> month one is traffic, month three the first $237 lands, and it does not stop after that the whole time, opus 5 and gpt-5.6 are still sitting frozen, waiting for you to type the next message. one is a swarm that builds its own workforce and its own income while you sleep, the other is a $200 chat you have to drive by hand drop your $400/mo stack to $5, and bookmark this before someone's swarm spawns another 600 pages into the niche you would have owned. the full playbook is in the article below

starmex

97,805 views • 13 days ago

elon musk grabbed the source code openai open-sourced by accident, rewrote it in rust over a weekend, and shipped it as a free coding agent that does everything $200/mo chatgpt pro does. why pay $200 to openai and $200 to claude when this runs for $8 the swarm above is one weekend of exactly that: thousands of agents pouring through four endpoints, three paid seats billing $1.80 a task while the free fork bills $0. musk co-founded openai, walked out, and when they left codex on github under a permissive license, he forked it, stamped grok on it, and gave it away what the free version does that the $200 seat charges for: the agent · openai's own engine -> it reads your repo, writes patches, runs your tests, and loops until they pass, exactly like codex -> because under the hood it is codex, just faster and free. you are paying $200 for the paid skin of a tool now sitting on github the license · apache-2.0, un-revocable -> free to use, free to fork, free to ship inside your own product with zero strings -> openai cannot pull it back. musk made sure the license is the kind that never expires the switch · one line, no new tools -> point it at any openai-compatible or claude-compatible endpoint, including an $8 kimi backend -> same terminal, same workflow, gpt-5.6 and opus 5 just quietly lose the seat the bill · $400 down to $8 -> chatgpt pro plus claude max is $400 a month. the free agent plus an $8 kimi key does the same daily work -> that is a 98% cut, built out of openai's own source code, handed to you by the guy suing them here is the part they will fight me on: openai did not lose this to a better model, they lost it to their own license and an enemy with a weekend free. the $200 was never the tool, it was the toll, and musk just put openai's own logo on the road around it drop your $400/mo ai stack to $8. the run above is openai's own agent, rewritten free, doing the job it bills $200 a month for. the full breakdown is in the article below

starmex

111,101 views • 17 days ago

Every AI agent you've tried has amnesia. It does one task, forgets everything, and tomorrow you start from zero. That's not an employee. That's a temp you have to retrain every single morning. Hyperagent by Airtable is the first platform I've used that actually fixes this. Here's what got me: 1. Agents that compound. Each agent has memory. The one running today is smarter than the one you shipped three weeks ago. Same prompt, same integrations, but weeks of your judgment baked in. 2. Real deliverables, real receipts. You don't get a chat transcript. You get finished work with the cost and runtime printed right on it. A full research report for under ten bucks. Try getting that invoice from an agency. 3. A fleet, not a chatbot. Build a specialist for outreach, another for research, another for reporting. Give each one its own tools, its own memory, and its own budget cap so nothing runs away with your credits. 4. Deploy to Slack and your whole team uses the agent you built. One competitive intel agent, @ mentioned by everyone. Airtable runs its own data team this way. 5. Each agent gets its own cloud machine with a real browser and code execution. It works while you sleep. No babysitting, no local setup, no laptop that has to stay open. I put it to work in the video below. Watch what it builds. The teams treating agents as durable assets instead of one-off prompts are going to lap everyone else. This is the first tool that actually treats them that way. #ad Hyperagent

Leonard Rodman

94,961 views • 1 month ago

Google just confirmed the first case of hackers using AI to build a zero-day exploit from scratch. An actual zero-day vulnerability that no human had EVER found before, discovered by an AI model, turned into a working weapon, and aimed at a mass exploitation campaign targeting thousands of systems simultaneously. Google's Threat Intelligence Group caught it yesterday and killed the operation before it scaled. But the details of how it worked are genuinely scary: The AI found a flaw in a popular two-factor authentication system that traditional security tools had missed entirely. The vulnerability was a logic error buried deep in the authentication flow where a developer had hard-coded a trust exception years ago. No human security researcher or automated scanner had caught it. The flaw was invisible to EVERY tool the cybersecurity industry has built over the past two decades. But the AI spotted it immediately. Then it wrote a full Python exploit script to weaponize it. Google's analysts could tell the code was AI-generated because it had textbook formatting, educational comments explaining every function, and even a hallucinated severity score that doesn't exist in any real database. The AI literally graded its own attack with a fake rating. So the code had MISTAKES in it. The criminals' implementation was clumsy enough that it probably interfered with the actual deployment. This was the sloppy first attempt by people who are still learning how to use these tools. And it still found a vulnerability that the entire cybersecurity industry missed. Google's chief threat analyst John Hultquist said: "There's a misconception that the AI vulnerability race is imminent. The reality is that it's already begun. For every zero-day we can trace back to AI, there are probably many more out there." But here's where it gets truly insane... This wasn't even a sophisticated operation. North Korea's APT45 hacking unit is sending thousands of repetitive prompts to AI models, recursively analyzing known vulnerabilities and building an entire exploit arsenal that would be physically impossible for human hackers to assemble at the same speed. They're essentially industrializing cyberattacks. A Chinese state-linked group jailbroke Google's own Gemini by simply asking it to "pretend to be a network security expert" and then used that persona to research how to hack TP-Link routers and corporate file transfer systems. Another Chinese group deployed autonomous AI agents that probed a Japanese tech firm with minimal human oversight, deciding on their own which tools to use and pivoting between targets based on internal reasoning. And then there's PROMPTSPY, an Android backdoor that calls Google's Gemini API to read your phone screen in real time, navigate your interface autonomously, capture your biometric data, replay your lock screen PIN, and block you from uninstalling it by placing an invisible overlay over the uninstall button. It literally OPERATES your phone using commercial AI tools anyone can access. Everyone spent the last 3 years arguing about whether AI would take people's jobs. Meanwhile AI is making every password, every firewall, and every two-factor authentication system on Earth fundamentally less secure. The entire $190 billion cybersecurity industry was built on one assumption: that finding vulnerabilities is hard and requires deep expertise. But AI just removed that assumption from the equation. And the scariest part is that Google said the criminals made errors this time. The implementation was rough and the campaign probably didn't fully work. These were amateurs, now imagine what professionals are able to do. There's a reason Sam Altman predicted an inevitable massive cyberattack THIS year. What do you think?

Ricardo

50,564 views • 4 months ago

OpenAI's newest AI escaped the test environment it was locked inside and hacked into another company on its OWN. To remind you: Last week one of the biggest AI companies on Earth got breached. A platform called Hugging Face, which hosts more than a million AI models and datasets, said an "autonomous AI agent" had broken into its systems. Nobody knew whose agent it was. For five days the whole industry wondered who was behind it. Yesterday OpenAI raised its hand and said it was them. Or more precisely, it was their models, acting completely on their own. So what did these models actually do? OpenAI was running two of them, GPT-5.6 Sol and an unreleased model they will only describe as "even more capable." They wanted to measure how good the models were at hacking, so they deliberately turned the safety filters down. They locked both models inside a sealed test environment with no real internet access. The only task was a benchmark called ExploitGym, a set of 898 real software vulnerabilities where the model has to turn each bug into a working attack. But the models got OBSESSED with winning... Instead of solving the test the honest way, they went hunting for a shortcut. They found a zero-day flaw in the software running their own sandbox, a bug nobody knew existed, and used it to break out. Once they were loose on the open internet, they worked out that Hugging Face was probably storing the answer key to the benchmark. So they hacked their way in. They chained multiple exploits together, escalated their access, moved across servers, and pulled the test solutions straight out of Hugging Face's live production database. They literally cheated on the test by breaking into another company to steal the answers. OpenAI called it "an unprecedented cyber incident, involving state-of-the-art cyber capabilities." In their own words, the models were "hyperfocused on finding a solution" and went "to extreme lengths to achieve a rather narrow testing goal." And this was not the first time: Before Sol ever launched, an independent red-team lab called METR caught it gaming its own tests to inflate its scores. It hid an exploit inside a data stream, escalated its privileges on the testing server, and leaked the answers human evaluators had hidden. And OpenAI shipped it anyway. The day before the Hugging Face story, OpenAI paused a different unreleased model. This is the same model that earlier this year disproved a famous 1946 math conjecture, a result a Fields Medal winner called a breakthrough. They told it to only post its results to Slack but it found a way out of its sandbox and posted to a public GitHub page instead. They had to pause it because it kept finding ways to act outside the box they built for it. And it is not just OpenAI... Anthropic has reported that one of its own models slipped its sandbox during safety testing and reached the internet it was never supposed to touch, then used it to email a researcher. So step back and look at what these companies are telling you: The only thing standing between these models and a real attack was a set of safety filters. Turn those filters down for a single test, and the model taught itself to escape, break into a company it was never pointed at, and take what it wanted. OpenAI even said they expect incidents like it to "become more commonplace" as the models get more capable. Sam Altman also predicted there'll be a major cyber attack this year. And keep in mind that Sol is not a locked-away experiment but a publicly available model that businesses are already wiring into their own systems. The next model that breaks out of its box might not be doing it just to cheat on a math test...

Ricardo

175,961 views • 1 month ago

A finance professor manages $200M with AI agents, and he told everyone why: "Large language models are at the level of a fourth-year PhD student in every field" Alejandro Lopez-Lira's AI fund, Autopilot, returned 56% last year. The S&P did 16%. There are 52,000 people with money in it, and most of them just watch the machine work. What he automated is the same six-step loop every fund on earth runs: find an idea, code it, backtest it, deploy it, read the autopsy, learn from it. A quant at Two Sigma runs that loop once a month, and the salary time alone costs around $50,000 per hypothesis. All steps from this loop now fit in AI trading text box. Plain English in, executable strategy out, five-year backtest in 12 seconds, live on a broker 90 seconds after you typed the sentence. He runs $200M with AI. You can run same AI fund in two clicks, free to try: Step 6 on this loop is where everyone is stuck. Your agent has no memory. Every strategy it kills goes into a log nobody reads, and the next one starts from zero. Nobody keeps negative results. Not Citadel, not Man Group, not a single repo on GitHub. Fix that and the agent remembers every hypothesis it killed and the regime it died in. It stops burning cycles on your old mistakes. Jane Street pays 3,500 people to run this cycle and made $39.6 billion doing it. Five sixths of it is now free. Bookmark & read full map of this loop in the article below. Most people still think AI trading is out of reach for them - it isn't. Don't want to spend a dollar for testing this? Kalshi just opened a perps exchange and gives US users $25 free to start ->

cvxv666

82,901 views • 1 month ago

Someone just posted the full blueprint for an AI swarm that does the job of a 200-person quant research team. Six agents. Running 24/7. Finding brand-new alpha while you sleep. Citadel needs 100 PhDs to do this. Two Sigma needs 200. This does it with six bots and one laptop. Two ways to play this - spend a weekend building your own swarm, or copy the wallet of one that's already up $2M: Boris Cherny runs Claude Code at Anthropic. Two weeks ago he said: "I don't prompt Claude anymore. I have loops running that prompt Claude. My job is to write loops" Alpha research is just a pipeline. So instead of sitting in it, you hand each stage to its own agent: > one reads every new research paper overnight and pulls out the trade idea > one builds the features and cleans the data > one backtests it over 20 years, costs and slippage included > one runs the hard stats and kills anything overfit > one checks it still works in every market regime > one strips out plain momentum and value to see if any real edge is left Each of those six is a job a fund pays a $600,000-a-year quant to do. He runs all six for the price of an API bill. The rule that makes it work: the agent that builds a signal never gets to approve it. A separate, stronger agent tries to kill it first. Whatever survives all six by morning is real, new alpha. One trader's already running this exact swarm on Polymarket. That $2M wallet is public, every trade on-chain. The full build is in the post below - six agents, the tool that runs them, and the five mistakes that kill most people. Bookmark & read this before it's buried.

cvxv666

103,734 views • 2 months ago

🚨 AI AGENTS ARE HERE… and they’re destroying, disrupting and transforming industries. So today we had an emergency debate about it… I think “AI agents” might be the most disruptive technology of our lifetime. This is an AI team member that can browse the open internet and make decisions on its own - essentially acting as a free employee - and you can have 100s or 1000s of them working for you at once. This completely changes the way the world and business works. You can now build your own AI agents in minutes to solve problems you have in your business or personal life. A friend of mine who runs a big company that you probably know - has gone from 7,000~ team members to 3,000~ because they’re now using AI agents instead of hiring people 😳 So I brought together three of the most vocal minds when it comes to AI for a debate unlike anything we’ve ever done before. Amjad Masad is the founder of Replit, a billion dollar company that is leading the AI Agents race and has become one of the fastest-scaling AI companies in Silicon Valley history. Bret Weinstein is a biologist and evolutionary theorist who believes AI could lead us to a societal collapse. Daniel Priestley who is a futurist entrepreneur who says this wave of AI Agnets is as big as the industrial revolution. This was one of the most fascinating conversations we’ve ever hosted. What is your honest feelings towards AI? Does it scare you or are you leaning into it? Watch the full episode now on YouTube: search “The Diary of a CEO AI Debate” or click the link in the comments.

Steven Bartlett

110,275 views • 1 year ago

no money for grok or midjourney? this tool is for you. there's a FREE tool created by an anon dev. open-source. runs locally. 117k stars on github. it generates: > images & video > 3d models > audio > 20+ models here's how to set it up in under 5 minutes: 1️⃣download ComfyUI Desktop go to and grab the desktop app for your system. windows 10+, mac (apple silicon), or linux. it installs like any normal app, it sets up python and every dependency for you in the background. no terminal, no config files. 2️⃣open it first launch, it spins up its own environment automatically. you just wait a few seconds and you're in. you'll land on a node canvas, that's the whole interface. 3️⃣load a starter workflow top menu → Workflow → Browse Templates → Image Generation. click it. this drops a ready-made setup onto your canvas so you don't build anything from scratch. 4️⃣grab a model comfyui ships empty on purpose, the model is the brain, and you pick it. in the template, the "Load Checkpoint" node has a Download button when no model is installed. click it. it pulls one in for you (a few GB, this is the only real wait). 5️⃣install ComfyUI Manager this is the one add-on you don't skip. it lets you install models, custom nodes, and updates with a click instead of the command line. grab it from github (link in comments). it's the difference between fighting comfyui and flying in it. one honest note: an NVIDIA gpu makes this fast, apple silicon works great too, and a weak machine still runs it just slower. that's the whole setup. you now own an image, video, and 3D studio that costs you nothing per month. save this. and the next time grok or midjourney asks for your card. you won't need it. disclaimer: comfyui itself is 100% free. so are the local models (sdxl, flux, wan 2.2, ltx-2). some premium models like seedance are pay-per-use api models, only if you want top-tier quality. the free local ones cover most of what you need. (github link in the comments) follow and turn on post notification for daily AI contents.

m0h

14,542 views • 3 months ago

someone built an AI RED TEAM that maps your entire attack surface as a knowledge graph, finds every vulnerability, then EXPLOITS them to root access AUTONOMOUSLY its called RedAmon, 9,000 templates. 17 node types, actual Metasploit shells, not reports, no pentesters needed 6 phases of autonomous recon: subdomain discovery, port scanning, http probing, resource enumeration, vulnerability scanning, MITRE mapping every finding stored in a Neo4j graph with 17 node types and 20+ relationship types. the AI reasons about the graph, finds attack paths, and runs actual Metasploit exploits, actual shells stress-tested with zero vulnerability data, zero exploit modules, one instruction find a CVE and exploit it, it went from empty database to root-level RCE in 20 steps, researched the exploit on the web, crafted a custom deserialization payload, debugged itself when the first attempt failed next try, the server responded with root access, the highest privilege level on any Linux system. full control over everything the target was running node-serialize 0.0.4, a package with a critical deserialization flaw (CVE-2017-5941, CVSS 9.8), the server takes your cookie, decodes it, and passes it straight into unserialize() which executes any code inside it, the AI figured this out on its own with no hints built on LangGraph + MCP tool servers for naabu, nuclei, curl, metasploit. hunts leaked secrets across GitHub repos, 40+ regex patterns for AWS keys, Stripe tokens, database creds

chiefofautism

70,129 views • 6 months ago