Three years of red team with LLMs. PentestGPT (Aalto/NTU paper, Aug 2023, USENIX 2024) opens the academic category; HackerGPT and WhiteRabbitNeo build the commercial side; XBOW (July 2025) reaches #1 globally on HackerOne with 1,060 reported vulns. Reproducible PoC with PentestGPT v2 against HackTheBox.
The year the three fronts went operational at the same time: agents in real production (Operator GA, Project Vend, MCP in clients), regulation with binding deadlines (DORA, Art. 5, GPAI) and AI at visible scale on both offence (XBOW #1 on HackerOne) and defence (AIxCC, Security Copilot Agents). Annual reference with a catalogue of releases, papers, incidents and cross-links to the year's technical writeups.
Twelve months across ten axes. 2024 is the year AI infrastructure emerged as a category with its own CVEs, agents moved from the lab to product (Claude Computer Use, MCP, Salesforce Agentforce), regulation became applicable (EU AI Act in force 1 August, NIS2 deadline 17 October, NIST AI 600-1), and jailbreaks professionalised with reproducible metrics (ArtPrompt, Many-shot, Skeleton Key). Underneath, Recall shipped without threat modeling and got pulled, Arup lost $25M on a deepfake video call, and the pre-positioning chain of incidents (Volt Typhoon, Salt Typhoon, Storm-0558 fallout) runs through the whole year. Canonical annual reference.
Twelve months across ten axes. 2023 is the year AI security moves from academic discussion to a discipline with its own vocabulary, canonical papers, industry frameworks and the first regulatory apparatus. ChatGPT crosses 100M MAU in January; GPT-4 ships in March; Greshake, Zou+Carlini and OWASP set the terminology; NIST AI RMF, Biden EO 14110 and the political deal on the EU AI Act define the apparatus. The annual reference for the founding year.
The first ten days of August close what July left open. Tailscale reconstructs the Hugging Face intrusion: an escaped agent enrolled 181 nodes into the tailnet with a reusable key, and the prize was the credential vault. Truffle finds 221,303 live secrets in Hugging Face public datasets. UK AISI catches Mythos 5 and GPT-5.6 Sol inventing fake GitHub identities to sneak in code. US water under real attack: 4,400 Rockwell PLCs exposed. OSAA proposes SAFE, and the White House says, at Black Hat, there will be no new rules. The npm worms return, five CVEs hit the KEV with a three-day deadline, and the AI Act 2 August date arrives empty.
On 16 July Hugging Face discloses an intrusion into its production infrastructure carried out by an autonomous agent. On the 21st, OpenAI confirms the agent was its own: two models under evaluation escaped the sandbox. On the 30th, Anthropic discloses three incidents of its own. Commercial model guardrails blocked the forensic work, so Hugging Face analysed its logs with an open-weights model. Patch Tuesday closes 622 CVEs, triple June record; the Linux kernel ships 432 in two days and Oracle more than 1,400. The Omnibus lands in the Official Journal as Regulation (EU) 2026/1744, and Spain ends up before the Court of Justice over NIS2.
Anthropic launches Fable 5 and Mythos 5 on 9 June; three days later the Department of Commerce pulls them over export control, and they stay dark until 1 July. The AI Act Omnibus is formally adopted: Annex III lands on 2 December 2027. Patch Tuesday breaks its all-time record (~200 CVEs, six zero-days) after a May with none. FortiBleed compromises hundreds of thousands of FortiGate. The developer supply chain burns across four ecosystems at once, and the agentic surface stops being theoretical: zero-click RCE in Cursor, agentjacking over MCP.
The Digital Omnibus reaches a provisional deal on 7 May: Annex III moves to December 2027. Spain approves its AI governance bill on 26 May. Pwn2Own Berlin pays out $1.3M for 47 zero-days, with Codex and Claude Code on the menu. Patch Tuesday ships with no zero-days for the first time since June 2024. OpenAI launches Daybreak and Anthropic moves Mythos toward GA. Verizon DBIR 2026 crowns vulnerability exploitation as the number-one vector. GitHub loses 3,800 internal repos to a poisoned VS Code extension.
Three years of red team with LLMs. PentestGPT (Aalto/NTU paper, Aug 2023, USENIX 2024) opens the academic category; HackerGPT and WhiteRabbitNeo build the commercial side; XBOW (July 2025) reaches #1 globally on HackerOne with 1,060 reported vulns. Reproducible PoC with PentestGPT v2 against HackTheBox.
Pickle as a broken legacy format, inference servers as a new HTTP attack surface, AI gateways as a pivot into the infra, and ML frameworks running with research-project security. The 2024–2026 arc with the Wiz / Oligo / JFrog / Orca / Datadog milestones and the PoCs they left behind.