This is seriously impressive, and if you have used agents enough you're not surprised at all. Like the time I asked it to find the IP address of a vm, so it ssh'd into the VMHost and scanned the arp tables to find the MAC address for IP resolution. Or the time it used Docker on the machine to bypass the fact that the user doesn't have sudo. If it's possible, given sufficient time and resources, it will find a way. Th…
Not to shit on the hype, but these are reasonably documented methods that surely are part of the training data
When seeing how agents put together exploit chains they are far better than most people, you start getting to the point that they are just below the capabilities of the top researchers. Now remember that quantity is a quality itself and while there aren't that many good cyber security researchers, we're shitting out thousands of GPUs per day.