Armory Defense sets offensive AI loose to attack companies from within: proof that cyberdefense can no longer wait weeks

🕒 Published on Zendoric: July 31, 2026 · 15:01
Israel's Armory Defense is launching AI agents that attack companies like a real adversary to show, with proof rather than theoretical alerts, which breaches are exploitable. The company says one critical vulnerability went from taking weeks to falling in 40 minutes with AI: the figure that sums up the sector's shift.
By Zendoric · July 31, 2026.
Israel's Armory Defense, founded in 2023, has unveiled Offensive Agentic-AI Simulations, the core of its platform for continuous validation of cyberattack exposure. The pitch: autonomous artificial intelligence agents that attack an organization's external surface —its internet-facing systems— in a controlled way, replicating the behavior of a real adversary instead of merely scanning and listing possible flaws.
What sets it apart from traditional vulnerability scanning is the proof. According to the company, its agents do not stop at detecting a breach: they exploit it safely and deliver evidence of real impact, organized into "Hackbooks" —sets of attacks by domain, such as authentication abuse, API exploitation, database attacks or validation of known CVEs—. Alon Aharon, co-founder and CEO of Armory Defense, sums up the pitch this way: "We don't find risk, we prove it."
The figure the company itself uses to justify the launch is the most revealing part of the announcement: a critical VPN vulnerability with a CVSS score of 9.8 (the standard severity scale, where 10 is the maximum) that previously took weeks to turn into a working exploit was weaponized, according to Armory Defense, in about 40 minutes with an AI-guided workflow. It is the company's own figure, without independent verification, but consistent with what we have been documenting in other pieces: agentic workflows brutally compress the time between a flaw being published and someone turning it into a weapon.
That is the underlying issue, beyond the specific product. The pentest —the one-off security audit, typically annual— was born for a world where building an exploit took weeks of specialized work. If that cost collapses to minutes, a snapshot of a company's security expires almost instantly. Broadly speaking, the continuous exposure validation industry (what the sector calls CTEM, "continuous threat exposure management") has been growing for a couple of years for this very reason; Armory Defense —agentless, with no software to install on the client's systems— is one more example of that trend, not the first.
Our reading: this is the defensive face of a phenomenon we have already flagged on its offensive side, the agentic industrialization of fraud and digital espionage. The same capability that lets an attacker chain vulnerabilities at machine speed is not exclusive to the bad guys: it also arms the defender, and in theory sooner, because the defender knows its own infrastructure better. Those who should worry in the short term are not so much the companies with a budget to hire continuous validation, but those still relying solely on the annual audit: the gap opens between those who automate their defense and those who do not.
In the long run, this AI-versus-AI race in cybersecurity is one more piece of the trust infrastructure that the mass deployment of artificial intelligence itself requires. An economy resting on autonomous agents —buying, negotiating, operating critical systems— is only viable if the security layer is as fast as the threats it faces. Companies like Armory Defense do not solve cybercrime at its root, but they normalize a defense that moves as fast as the attack, and that is a necessary, though not sufficient, condition for the abundance AI promises not to be built on foundations anyone can knock down in 40 minutes.
🔗 Related on Zendoric
- Anthropic takes AI distillation to the Senate: when copying agentic capabilities becomes a matter of state · 2026-06-26
- Nokia brings Gemini agents to the network: automating without taking the engineer out of the loop · 2026-06-24
- Anthropic versus Alibaba: the 'distillation attack' that tests AI's competitive moat and the sector's trillion-dollar valuation · 2026-06-28


