<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Autonomous defense · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/autonomous-defense/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/autonomous-defense/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on autonomous defense, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Correction to a finding (reconfirmed as corroborated): LLM agents fall well short of reliable performance on realistic threat-investigation and threat-hunting benchmarks built from security logs.</title>
<link>https://agentic-cyber-explorer.pages.dev/findings/soc-agents-weak-on-realistic-benchmarks/</link>
<guid isPermaLink="false">correction:soc-agents-weak-on-realistic-benchmarks:2026-09-25:corroborated</guid>
<pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
<category>Correction</category>
<description>Correction: CyberSOCEval tests multiple-choice question answering, not agents on investigation or hunting. Corroboration rests on Simbian's Cyber Defense Benchmark, where the best of five models flagged 3.8% of malicious events in raw logs.</description>
</item>
<item>
<title>Google's PageBreak agent finds over 500 XSS bugs in its own web apps using deterministic validators</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-pagebreak-web-vulnerability-agent-2026/</link>
<guid isPermaLink="false">event:google-pagebreak-web-vulnerability-agent-2026</guid>
<pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google's Product Security team describes PageBreak, an internal agent mostly using Gemini models that hunts vulnerabilities in Google's first-party web applications and only reports findings confirmed by non-AI validators against running applications. Google reports over 500 XSS vulnerabilities found with near-zero false positives, while apps on its high-assurance web frameworks yielded only 2 XSS bugs as of 4 September 2026. It shows a concrete design for suppressing AI-generated false positives. Google also reports that apps built on its secure-by-design frameworks yielded very few bugs to the agent, though that comparison is an uncontrolled self-report.</description>
</item>
<item>
<title>US Cyber Strategy for America commits to adopting agentic AI for network defense and disruption</title>
<link>https://agentic-cyber-explorer.pages.dev/events/us-cyber-strategy-for-america-agentic-ai-2026/</link>
<guid isPermaLink="false">event:us-cyber-strategy-for-america-agentic-ai-2026</guid>
<pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Trump administration's Cyber Strategy for America commits to securing the AI technology stack, adopting AI-powered cybersecurity for federal networks, and using AI-enabled tools to detect, divert and deceive threat actors. It states the US will rapidly adopt and promote agentic AI to securely scale network defense and disruption. It is a US national cyber strategy that names agentic AI as a tool for both defense and offensive disruption.</description>
</item>
<item>
<title>PNNL uses a Claude-based agent to speed adversary emulation against a water treatment plant model</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-pnnl-critical-infrastructure-emulation-2026/</link>
<guid isPermaLink="false">event:anthropic-pnnl-critical-infrastructure-emulation-2026</guid>
<pubDate>Thu, 08 Jan 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Anthropic reports that Pacific Northwest National Laboratory built a scaffold around Claude Sonnet 4 to automate adversary emulation against a high-fidelity cyber-physical model of a water treatment plant used for CISA. PNNL estimates attack reconstruction took three hours instead of multiple weeks; in one run the model switched to a different known privilege-escalation technique when a provided tool failed. Faster adversary emulation lets critical-infrastructure defenders re-test controls more often, while the model's improvisation shows why such agents need tight scoping.</description>
</item>
<item>
<title>NIST releases preliminary draft Cyber AI Profile (IR 8596) under CSF 2.0</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nist-cyber-ai-profile-preliminary-draft-2025/</link>
<guid isPermaLink="false">event:nist-cyber-ai-profile-preliminary-draft-2025</guid>
<pubDate>Tue, 16 Dec 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>NIST published a preliminary draft Cybersecurity Framework Profile for Artificial Intelligence, aligned with CSF 2.0. It is organized around three focus areas: securing AI systems, using AI for cyber defense, and thwarting AI-enabled cyberattacks, with comments due January 30, 2026. It is the vehicle through which NIST intends to fold AI-enabled attack and defense, including agents, into the CSF outcomes organizations already report against.</description>
</item>
<item>
<title>CISA, ASD and partners issue principles for securely integrating AI, including agents, into OT</title>
<link>https://agentic-cyber-explorer.pages.dev/events/cisa-principles-ai-in-operational-technology-2025/</link>
<guid isPermaLink="false">event:cisa-principles-ai-in-operational-technology-2025</guid>
<pubDate>Wed, 03 Dec 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>CISA and the Australian Signals Directorate, with NSA, FBI and national cyber agencies of Canada, Germany, the Netherlands, New Zealand and the UK, published four principles for integrating AI into operational technology. The guidance explicitly covers machine learning, LLM-based AI and AI agents because of the security and safety challenges they pose in industrial environments. It is multinational guidance that addresses AI, including agents, acting in safety-critical industrial control environments.</description>
</item>
<item>
<title>Microsoft RCT finds phishing triage agent raised analysts' true positives per minute up to 6.5x</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-phishing-triage-agent-rct-2025/</link>
<guid isPermaLink="false">event:microsoft-phishing-triage-agent-rct-2025</guid>
<pubDate>Mon, 17 Nov 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Microsoft reports a randomized controlled trial of its own Security Copilot Phishing Triage Agent. In the trial, 167 external security analysts each triaged a 25-email queue drawn from a curated corpus of emails reported by Microsoft employees. In the scenario where the agent classified every corpus email correctly, analysts with the agent found 6.5 times as many true positives per minute as the control group and scored 77% higher on F1; with the agent's accuracy set to 80% and a 20% malicious rate, the productivity gain fell to 3.1 times. Analysts with the agent spent 53% more time on malicious emails and did not simply confirm its malicious verdicts, but they were more likely to accept its benign verdicts, including planted false negatives. It is one of the few randomized measurements of a commercial SOC triage agent's effect on analysts, and it reports automation bias toward the agent's benign verdicts alongside the productivity gains. It is a vendor study of its own product in a controlled task, not live operations.</description>
</item>
<item>
<title>Paper frames autonomous cyber defence as multi-objective RL balancing defence against service disruption</title>
<link>https://agentic-cyber-explorer.pages.dev/events/morl-resilient-cyber-defence-2025/</link>
<guid isPermaLink="false">event:morl-resilient-cyber-defence-2025</guid>
<pubDate>Fri, 05 Sep 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>A paper in Applied AI Letters argues that single-objective RL defenders built on hand-weighted rewards cannot adapt at inference time to competing goals such as stopping intrusions versus avoiding downtime. It presents a simple multi-objective network defence game in which defending against red agents must be balanced with preserving network services. It formalises the trade-off between defensive action and operational disruption that any autonomous defender must manage.</description>
</item>
<item>
<title>ACM Computing Surveys review sets readiness criteria for deploying autonomous network defence agents</title>
<link>https://agentic-cyber-explorer.pages.dev/events/acm-survey-autonomous-cyber-network-defence-2025/</link>
<guid isPermaLink="false">event:acm-survey-autonomous-cyber-network-defence-2025</guid>
<pubDate>Sat, 30 Aug 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>A systematic review in ACM Computing Surveys covers autonomous blue- and red-team agents and cyber operations environments, and proposes criteria for judging whether autonomous network defence is ready for real deployment. It identifies gaps in explainability, continual learning under evolving threats, and realistic training environments. It is a reference synthesis for what evidence would be needed before letting autonomous defenders act on live networks.</description>
</item>
<item>
<title>AIxCC final: Team Atlanta wins as systems patch 43 of 54 found synthetic bugs and find 18 real ones</title>
<link>https://agentic-cyber-explorer.pages.dev/events/darpa-aixcc-final-results-2025/</link>
<guid isPermaLink="false">event:darpa-aixcc-final-results-2025</guid>
<pubDate>Fri, 08 Aug 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>DARPA reports that seven finalist cyber reasoning systems analyzed over 54 million lines of code, found 54 unique synthetic vulnerabilities in 63 challenges and patched 43, and found 18 real non-synthetic vulnerabilities with 11 patches. Team Atlanta won $4 million, Trail of Bits $3 million and Theori $1.5 million; DARPA and ARPA-H added $1.4 million for real-world integration and four systems were open-sourced on the day. It is an organizer-verified, competition-scale measurement of autonomous AI vulnerability discovery and patching, with open-sourced systems others can reuse.</description>
</item>
<item>
<title>Microsoft's Project Ire agent autonomously reverse engineers and classifies malware</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-project-ire-malware-classification-2025/</link>
<guid isPermaLink="false">event:microsoft-project-ire-malware-classification-2025</guid>
<pubDate>Tue, 05 Aug 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Microsoft Research describes Project Ire, a prototype LLM agent that uses decompilers and binary analysis tools to reverse engineer software and classify it as malicious or benign, producing an auditable chain-of-evidence report. Microsoft reports 0.98 precision and 0.83 recall on a Windows driver dataset, but 0.26 recall on about 4,000 hard real-world files, and plans to deploy it in Defender as Binary Analyzer. It is a rare defensive-agent announcement that publishes both strong and weak results, including low recall on hard samples.</description>
</item>
<item>
<title>Paper proposes test and evaluation process with effectiveness metrics for RL cyber defence agents</title>
<link>https://agentic-cyber-explorer.pages.dev/events/dstl-evaluating-rl-cyber-defence-agents-2025/</link>
<guid isPermaLink="false">event:dstl-evaluating-rl-cyber-defence-agents-2025</guid>
<pubDate>Fri, 27 Jun 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>A paper in Applied AI Letters by QinetiQ researchers sets out a test and evaluation process for cyber defence agents covering performance, effectiveness, resilience and generalisability, and demonstrates its low-fidelity stage on CAGE Challenge 2 RL agents in CybORG. It introduces Measures of Effectiveness tailored to cyber defence alongside RL reward and tests agents under environment perturbations not seen in training. It proposes defence-specific effectiveness metrics and robustness tests to complement RL reward when judging whether a defensive agent can be trusted.</description>
</item>
<item>
<title>UC Santa Cruz study integrates LLM agents into CAGE 4 and finds RL defenders still outperform them</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ucsc-llms-autonomous-cyber-defenders-cage4-2025/</link>
<guid isPermaLink="false">event:ucsc-llms-autonomous-cyber-defenders-cage4-2025</guid>
<pubDate>Wed, 07 May 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Researchers led by UC Santa Cruz integrated LLM agents into the CybORG CAGE 4 multi-agent defence environment and proposed a communication protocol for mixed LLM and RL teams. In their runs an all-RL team scored far better reward than an all-LLM (GPT-4o-mini) team and acted about 104 times faster, though the authors highlight LLM explainability and note the environment was designed for RL agents. The authors describe it as the first study of LLM agents in a multi-agent autonomous cyber defense environment, and it cautions against assuming LLMs beat trained RL policies.</description>
</item>
<item>
<title>Microsoft announces Security Copilot agents for phishing triage, alert triage and remediation</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-security-copilot-agents-2025/</link>
<guid isPermaLink="false">event:microsoft-security-copilot-agents-2025</guid>
<pubDate>Mon, 24 Mar 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Microsoft announced Microsoft-built Security Copilot agents, including a Phishing Triage Agent in Defender, alert triage agents in Purview, a Conditional Access Optimization Agent, a Vulnerability Remediation Agent in Intune and a Threat Intelligence Briefing Agent, plus five partner agents. Preview was planned from April 2025; the announcement contains no evaluation of agent accuracy. It marked a major vendor's shift from assistant-style copilots to semi-autonomous triage and remediation agents inside SOC tooling.</description>
</item>
<item>
<title>Frontier Model Forum issue brief maps defensive uses of frontier AI in cybersecurity</title>
<link>https://agentic-cyber-explorer.pages.dev/events/fmf-issue-brief-ai-for-cyber-defense-2024/</link>
<guid isPermaLink="false">event:fmf-issue-brief-ai-for-cyber-defense-2024</guid>
<pubDate>Fri, 22 Nov 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The Frontier Model Forum, an industry body of frontier labs, published an issue brief on using frontier AI for cyber defense. It lists use cases including process automation for incident response, natural-language querying and analysis, vulnerability discovery and fixing, open-source intelligence and training, and recommends designing for human-AI collaboration rather than full automation. It records the lab consortium's stated position on defensive agent use before autonomous defense became a policy priority in 2026.</description>
</item>
<item>
<title>AIxCC semifinal: AI systems find 22 synthetic vulnerabilities, patch 15, and find one real SQLite bug</title>
<link>https://agentic-cyber-explorer.pages.dev/events/darpa-aixcc-semifinal-results-2024/</link>
<guid isPermaLink="false">event:darpa-aixcc-semifinal-results-2024</guid>
<pubDate>Sun, 11 Aug 2024 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>DARPA reports that in the AIxCC semifinal at DEF CON 32, nearly 40 cyber reasoning systems were tested on challenge projects based on Jenkins, the Linux kernel, Nginx, SQLite3 and Apache Tika. Competitors' systems found 22 unique synthetic vulnerabilities, patched 15, and found one real-world SQLite3 bug; seven teams advanced with $2 million each and must open-source their systems after the final. It gave organizer-verified numbers on how well AI cyber reasoning systems could find and patch vulnerabilities in challenge projects built on widely used open-source software.</description>
</item>
<item>
<title>DARPA CASTLE program awards contracts to train reinforcement-learning agents for network defence</title>
<link>https://agentic-cyber-explorer.pages.dev/events/darpa-castle-program-awards-2024/</link>
<guid isPermaLink="false">event:darpa-castle-program-awards-2024</guid>
<pubDate>Mon, 15 Jul 2024 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>DARPA's CASTLE program aims to build a toolkit that instantiates realistic network environments and trains AI agents, using reinforcement learning, to harden networks against advanced persistent threats. The program page says it will publicly release toolkit-generated datasets as defensive benchmarks; public contract records show awards under solicitation HR001123S0002 in mid-2024. It is a government-funded effort to create repeatable, measurable environments and datasets for evaluating autonomous defensive agents.</description>
</item>
<item>
<title>TTCP releases CAGE Challenge 4, a multi-agent autonomous cyber defence environment</title>
<link>https://agentic-cyber-explorer.pages.dev/events/cage-challenge-4-multi-agent-defence-2024/</link>
<guid isPermaLink="false">event:cage-challenge-4-multi-agent-defence-2024</guid>
<pubDate>Tue, 20 Feb 2024 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>CAGE Challenge 4, run under The Technical Cooperation Program, asks entrants to build five cooperating blue-team agents that defend a segmented fictional military network against randomized red agents while green agents generate legitimate activity. The challenge ran from February to May 2024 in the CybORG simulator, scored by mean reward over 100 randomized 500-step episodes, and the environment remains public. CAGE 4 is a shared, reproducible environment that later work, including LLM-agent defenders, uses to compare defensive agents.</description>
</item>
<item>
<title>DARPA launches the AI Cyber Challenge to build AI systems that find and fix open-source vulnerabilities</title>
<link>https://agentic-cyber-explorer.pages.dev/events/darpa-aixcc-launch-2023/</link>
<guid isPermaLink="false">event:darpa-aixcc-launch-2023</guid>
<pubDate>Wed, 09 Aug 2023 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>At Black Hat USA 2023, DARPA announced the AI Cyber Challenge (AIxCC), a two-year competition to build AI-driven systems that automatically find and fix vulnerabilities in critical open-source software. Anthropic, Google, Microsoft and OpenAI agreed to provide technology and expertise to competitors, OpenSSF served as challenge advisor, and semifinal and final rounds were scheduled for DEF CON 2024 and 2025. AIxCC became a large public test of LLM-based cyber reasoning systems for defensive vulnerability discovery and repair.</description>
</item>
<item>
<title>CETaS and CSET report maps barriers to deploying reinforcement-learning cyber defence agents</title>
<link>https://agentic-cyber-explorer.pages.dev/events/cetas-cset-autonomous-cyber-defence-roadmap-2023/</link>
<guid isPermaLink="false">event:cetas-cset-autonomous-cyber-defence-roadmap-2023</guid>
<pubDate>Thu, 15 Jun 2023 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>A joint report from the Alan Turing Institute's CETaS and Georgetown's CSET assesses autonomous cyber defence, focusing on reinforcement learning (RL) agents trained in cyber gyms such as CAGE. It sets out technical challenges (combinatorial action spaces, reward design, transferability, securing the defender agents) and policy challenges (human-machine teaming, testing, liability), and recommends investment in gyms, test ranges, competitions and authorisation thresholds. It records how autonomous defence was framed before LLM agents entered the field, including the open question of when defensive agents may act without human approval.</description>
</item>
</channel>
</rss>
