started · updated
Cybermes and new open-source AI tools advance automated penetration testing
The cybersecurity landscape is seeing a rise in open-source, AI-driven autonomous agents designed for offensive security and penetration testing. Cybermes, an enterprise-grade framework, has released version 2.0.0. Developed by Zyrexnn, the tool utilizes a Hermes reasoning engine to automate the entire reconnaissance-to-reporting pipeline. It features a performance-optimized architecture using native Go binaries and includes over 50 security skills to address vulnerabilities such as authentication bypass and injection matrices. Notably, it employs a “zero-false-positive gate” that requires deterministic proof and reproducible scripts before documenting findings.
Other significant open-source tools in this sector include NVIDIA’s SkillSpector, which scans AI agent skills for risks, and PentestGPT, an agentic framework that automates asset discovery, vulnerability identification, and reporting. Additionally, platforms like Future AGI provide environments for evaluating and guardrailing LLM agents, while Chainloop serves as an evidence store for software supply chain security.