Close Menu
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
TechzLab – Tech News, Gadgets, Mobile & IT UpdatesTechzLab – Tech News, Gadgets, Mobile & IT Updates
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
TechzLab – Tech News, Gadgets, Mobile & IT UpdatesTechzLab – Tech News, Gadgets, Mobile & IT Updates
Home » I Watched AI Agents Try to Hack My Vibe-Coded Website
Latest in Tech

I Watched AI Agents Try to Hack My Vibe-Coded Website

adminBy adminJuly 30, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

A few weeks ago, I watched a small team of artificial intelligence agents spend roughly 10 minutes trying to hack into my brand new vibe-coded website.

The AI agents, developed by startup RunSybil, worked together to probe my poor site to identify weak spots. An orchestrator agent, called Sybil, oversees several more specialized agents all powered by a combination of custom language models and off-the-shelf APIs.

Whereas conventional vulnerability scanners probe for specific known problems, Sybil is able to operate at a higher level, using artificial intuition to figure out weaknesses. It might, for example, work out that a guest user has privileged access—something a regular scanner might miss—and use this to build an attack.

Ariel Herbert-Voss, CEO and cofounder of RunSybil, says that increasingly capable AI models are likely to revolutionize both offensive and defensive cybersecurity. “I would argue that we’re definitely on the cusp of a technology explosion in terms of capabilities that both bad and good actors can take advantage of,” Herbert-Voss told me. “Our mission is to build the next generation of offensive security testing just to help everybody keep up.”

The website targeted by Sybil was one I created recently using Claude Code to help me sort through new AI research papers. The site, which I call Arxiv Slurper consists of a backend server that accesses the Arxiv—where most AI research is posted—along with a few other resources, combing through paper abstracts for words like “novel”, “first”, “surprising” as well as some technical terms I’m interested in. It’s a work in progress, but I was impressed with how easy it was to cobble together something potentially useful, even if I had to fix a few bugs and configuration issues by hand.

A key problem with this kind of vibe-coded site, however, is that it’s hard to know what kinds of security vulnerabilities you may have introduced. So when I spoke to Herbert-Voss about Sybil, I decided to ask if it could test my new site for weaknesses. Thankfully, and only because my site is so incredibly basic, Sybil did not find any vulnerabilities.

Herbert-Voss says most vulnerabilities tend to be the result of more complex functionality like forms, plugins, and cryptographic features. We watched as the same agents tried probing a dummy ecommerce website with known vulnerabilities owned by Herbert-Voss. Sybil built a map of the application and how it is accessed, probed for weak spots by manipulating parameters and testing edge cases, and then chained together findings, testing hypotheses, and escalating until it breaks something meaningful. In this case, it did identify ways to hack the site. Unlike a human, Herbert-Voss says Sybil runs thousands of these processes in parallel, doesn’t miss details, and doesn’t stop. “The result is something that behaves like a seasoned attacker but operates with machine precision and scale,” he says.

“AI-powered pen testing is a promising direction that can have significant benefits for defending systems,” says Lujo Bauer, a computer scientist at Carnegie Mellon University (CMU) who specializes in AI and computer security. Bauer recently coauthored a study with others from CMU and a researcher from AI company Anthropic that explores the promise of AI penetration testing. The researchers found that the most advanced commercial models could not perform network attacks but developed a system that set high-level objectives like scanning a network or infecting a host, which enabled them to perform penetration tests.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

NYT Strands hints and answers for Wednesday, July 30 (game #514)

July 29, 2025

Doomed Exoplanet TOI-2109b Spirals Toward Its Star with Three Possible Fates

July 28, 2025

In the Latest Space Race, It’s China vs. SpaceX

July 27, 2025
Leave A Reply Cancel Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest
  • GitHub Copilot crosses 20 million all-time users | TechCrunch July 31, 2025
  • Watch the Battlefield 6 multiplayer gameplay reveal live to see if DICE can bring back the good ol’ days July 30, 2025
  • OnePlus 13, Nord 5 Series, Buds Pro 3, and More Go on Sale at Discounted Prices During OnePlus Independence Day Sale July 30, 2025
  • Some Windows 10 PCs are reportedly being offered a Windows 11 upgrade even though they don’t support the OS – here’s what to do if this happens to you July 30, 2025
  • Chromebook Plus laptops like Lenovo’s sleek, new 14-incher are getting free Gemini AI features – The Verge July 30, 2025
We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from Techzlab.

Tags
Apple artificial intelligence baiju bhatt ChatGPT cybersecurity data centers defense tech Dennis Lehane Digitalis Ventures doge Donald Trump electric vehicles Elon Musk evergreens EVs Exclusive Gallant Generative AI geoffrey maguire Google Grok In Brief Lauren Groff Lev Grossman Meta Microsoft Openai Part Perplexity Pinterest Redwood Materials rf kuang robotics slate slate auto SMBs social media SpaceX Spotify stem-cell therapy TC All Stage TechCrunch All Stage TechCrunch All Stage 2025 Tesla Trump Administration
Archives
Quick Link
  • Apps (264)
  • From the Editor (3)
  • Gaming (263)
  • Laptops (264)
  • Latest in Tech (264)
  • Mobiles (265)
  • Money (89)
  • Tech Insights (264)
Don't miss

Asus ROG Xbox Ally, ROG Xbox Ally X Price in Europe, Preorder Date Leaked

July 30, 2025

Google Chrome Gets AI-Powered Store Summaries to Improve Online Shopping Experience

July 29, 2025

Is Silicon Valley Losing Its Influence on DC?

July 28, 2025
Follow us
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
© 2025 Techzlab.com Designed and Developed by WebExpert.
  • Home
  • From the Editor
  • Money
  • Privacy Policy
  • Contact

Type above and press Enter to search. Press Esc to cancel.