Blog
Product
Announcing Cogent Attack Path Analysis: Find and Sever the Routes AI Agent Swarms Could Exploit to Your Crown Jewels
The age of autonomous cyber attacks is here. Cogent is your defensive counterpoint that deploys AI agents to find and fix machine-viable attack paths before adversaries do.
7 min read

In July, a swarm of roughly 700 AI agents broke into Hugging Face's production infrastructure. Those agents, operating beyond the scale of any human hacking team, took some 17,600 actions, harvesting credentials and moving laterally across its systems.
Models with these capabilities are now available to anyone. Z.ai released GLM-5.3 as an open-weight model in late August, and Anthropic's analysis found that it built working end-to-end exploits nearly as often as Claude Mythos Preview. Its safeguards can be removed for a few thousand dollars of compute. What happened at Hugging Face is a preview of what attackers will be able to do with models like this.
Exploited vulnerabilities are already the most common way breaches begin, accounting for 31% of initial access in the 2026 Verizon Data Breach Investigations Report. But a breach is rarely a single exploit. Attackers chain an exposed edge device to a stored credential, that credential to an overprivileged role, and that role to the data they came for. Human attackers abandon most of those chains because they are too long or too uncertain to be worth the effort. AI agents don't get tired. They work through every route methodically and keep going where a person would give up.
In Cogent’s Q4 Threat Research Report: Beyond the Human Horizon, Cogent Research found that for every attack path viable for a human attacker, there are three viable for an AI agent. The average enterprise now gains 34 new attack paths a month that only an AI agent would follow, up 386% in a year.
Today we're launching Cogent Attack Path Analysis so you can find and fix those paths at machine speed. It finds the routes to your crown jewels that an agent swarm would take, along with the ones a human hacking team would, across cloud, on-prem, identity, and code, by joining data your security tools keep separate. It verifies every hop with evidence your team can inspect, then finds the chokepoint: the one change that severs a path, and often other paths with it.
Attack paths are multiplying
New vulnerabilities are being published faster than security teams can work through them. Reports of critical and high-severity vulnerabilities from major software companies have "gone vertical" since the spring, as Andreessen Horowitz put it in a September analysis of Epoch AI data. Epoch AI counted about 2,500 critical and high-severity vulnerabilities from 21 major vendors and open-source projects in July alone, roughly five times their monthly record before April.

Each one can open a new route to a crown jewel. So can changes that never register as vulnerabilities at all: a firewall rule opened for a vendor, a role granted to a service account, a secret committed to a deploy pipeline, a new service put behind a load balancer. Environments change every day, and each change creates new combinations for an attacker to chain together.
Those chains rarely stay inside one part of the environment. Cogent Research found that 64% of attack paths cross domains that no single security tool observes. Your scanner sees the vulnerable appliance, your identity tooling sees the overprivileged service account, and your cloud security platform sees the exposed database. None of them sees the route that runs through all three.
How Attack Path Analysis works
Most vulnerability programs still judge each finding in isolation, such as a critical CVE on one server or a misconfiguration in one cloud account, even though fewer than 1% of those findings are exploitable where they sit. Attack path capabilities have existed for years, but they cover only some asset types and were built to model human attackers, with no view of how AI agent swarms operate. Attack Path Analysis brings data together across hybrid environments to find both the paths a human would take and the ones only an AI agent would follow. It works in four steps.
Builds one map from the tools you already run
Cogent connects signals from your existing tools into one graph of assets, identities, data, and controls that refreshes as your environment changes. Firewall rules, NAT, load balancer mappings, and attack surface data show what an attacker can reach. Scanner and runtime data show which vulnerable software is actually loaded, and EDR and WAF coverage separates live weaknesses from blocked ones.
Roles, secrets, and deploy pipelines show where a foothold leads, and business context such as data classification and CMDB records identifies your crown jewels.

Reasons like an attacker, whether human or AI
Cogent's AI agents then traverse the graph, starting at each crown jewel and working backward to the internet, so every path they report ends at an asset that matters. Cogent deploys AI agents that specialize in exploitability. They form competing hypotheses about how an attacker could get in and test each one against the evidence in the graph.
They look for two kinds of paths. Some are routes a skilled human team would take. Others chain flaws, credentials, and permissions into routes too long and uncertain for a human attacker to pursue. Those machine-viable paths are where an AI agent swarm has the advantage.
Cogent’s AI agents run on VR-1, our cyber reasoning model, as well as other frontier models. In Attack Path Analysis, our agents operate on a graph of your environment, including where your crown jewels are and how your network is laid out. In our testing, that context makes agents markedly more accurate, and it is information an outside attacker usually lacks.
Verifies every hop with evidence
A path is only useful if your team can trust it. At every hop, Cogent checks that the target is reachable, that the weakness is present, and that the attacker's next action would work. It reports a path only when every exploitable hop holds up. A hop blocked by EDR or a WAF fails that check, for instance.
Each hop cites its source and how fresh that source is, and is marked observed, inferred, missing, contradicted, or stale. Each path explains why it isn't rated higher or lower and lists the open questions that could change its rating, so your team can inspect the reasoning and challenge any part of it.
When no route reaches a crown jewel, Cogent says so and shows the closest partial path. If a new vulnerability is published or a configuration change fills the missing hop, that partial path becomes a complete route to your crown jewels. Near misses show you where to reduce risk before that happens.
Finds the best fix and sends it to its owner
Once a path is verified, the next question is where to break it. The obvious move is to patch the asset that raised the alert, which closes that one route. Attack paths often share hops, though. A single permission, secret, or trust boundary well away from the alerting asset can sit on several paths at once. That is the chokepoint: the point where one change breaks a path, and often other paths with it.
To find it, Cogent weighs the possible fixes for each path, from patches to permission cuts to secret rotation, and ranks them by how many paths each one closes, its blast radius, and the effort involved.
Each recommended change names the hop it removes and the paths it closes, so its owner can see why it matters. Cogent sends the path, its evidence, and the recommended change to that owner in the Cogent Action Queue as a single work item to review and act on.
Seven hops to 9 million customer records
Consider a path like this one. It starts with a remote code execution flaw on an internet-facing F5 BIG-IP. From the appliance, an attacker takes the Active Directory bind credential it stores. That credential belongs to an AD service account federated into AWS. With it, the attacker can assume a sync role, pivot to an ECS deploy role, push code to a Java payments service, and read the PostgreSQL database behind it, which holds 9 million customer records.

The path crosses an on-prem appliance, Active Directory, AWS identity, and a production workload, and Cogent verifies each hop. Patching the F5 would close this one entry point. Cogent determines that the chokepoint is the AD service account. Removing it from the AD group that federates it into AWS leaves the F5 with the directory access it needs to authenticate users, and a stolen bind credential no longer reaches the cloud. That one change severs this path and any other route that runs through the account.
Your own Defense Factory
In September, OpenAI described what it calls a Defense Factory: a continuous loop in which AI agents find, validate, and fix vulnerabilities. OpenAI built its own internal factory around its own first-party code. Cogent brings the same loop to the enterprise and extends it beyond code to the entire estate: infrastructure, cloud, endpoints, identities, network controls, and applications.
Attack Path Analysis is a central part of that loop. It tells you which risks to remove first and exactly which change will remove them. Cogent Autonomous Remediation carries out that change once you authorize it, and Cogent closes the path only after a rescan confirms the fix held. Teams can start in assistive mode, approving each change, and hand over more of the work as trust builds.
Where we're headed
Agent swarms are going to become the standard way attacks are run, and the models that can power them are already public. Limiting progress at the frontier won't change that. Defenders need equally capable AI on their side now.
Security has always trailed new technology. Cloud security had more than a decade to mature after enterprises moved to the cloud. Defenders won't get that much time with AI. The right defenses need to be in place in months.
Someone will eventually get a foothold in your environment. Our goal is that when they do, every route from that foothold to your crown jewels has already been severed.







