Have you tried the open source AI hacking agent Strix? 🤖
Strix integrated Caido as their proxy of choice to provide observability, human-in-the-loop and shared context to the agents. We are now working on native guardrails.
If you are building AI hacking agents, we can help you too!
More details 🔗 https://t.co/fG2DgHlhdC
You can read the full timeline, the technical breakdown, and how Strix's parallel agents validated the flaw on our blog here: 🔗 https://t.co/CYuANuXnVJ
We found a zero-authorization vulnerability in an a16z-backed DoD startup that exposed the data of active U.S. military personnel.
We tried to report it. They ignored us for 150 days.
Here is how our open-source AI agent found the ultimate OPSEC nightmare 🧵👇
Introducing Context-Aware Pentesting in Strix
The hardest vulnerabilities in modern apps are no longer simple code bugs.
They depend on understanding your architecture, user flows, roles, and business logic, which is where most automated pentesting still falls short.
Strix now brings persistent organizational context to every pentest, giving each run knowledge of your stack and learning from every finding and fix, so it can uncover the business logic and access control flaws generic testing misses.
https://t.co/1sGjuOUJo9
Introducing Strix PR Security Reviews
Developers are shipping faster than ever with AI. But making sure code is secure is now the real bottleneck.
Strix brings continuous pentesting to every pull request, with runtime validation and proof-of-exploit, blocking vulnerable code before it reaches production so teams can ship fast with confidence.
https://t.co/NgQbm72vvq
Strix found a critical auth bypass in etcd, one of the most used open-source components in cloud infrastructure.
Now published as CVE-2026-33413 (CVSS 8.8).
Read the full writeup:
https://t.co/iM9hv1lH0W
Introducing the new Strix Platform: continuous pentesting for modern apps.
Strix is an open-source framework for autonomous pentesting across apps, APIs, and repositories - helping teams find and validate vulnerabilities, generate fixes, and secure software faster.
Since our launch, we’ve had:
- 80,000+ users worldwide
- 15B+ LLM tokens processed daily
- 78,000+ vulnerabilities reported
- multiple CVEs assigned
- deployed by enterprise security teams worldwide
Today, we’re launching the Strix Platform for teams that want to run Strix continuously.
With Strix Platform, teams can:
- pentest their full stack continuously
- block vulnerable PRs from merge
- validate findings with proof-of-exploit
- get merge-ready fixes
- retest automatically
- track security posture over time
Security shouldn’t be your bottleneck.
Strix helps you ship faster and deploy with confidence.
Try it now 🔗↓
https://t.co/NGvz5wUHub
Adding on to this, we have our agent trying to find more about this attack and besides the [email protected] mail mentioned in the gist, the payload package was published by [email protected], a separate attacker account.
Will share more as we dig deeper.
Excited to announce our partnership with @CaidoIO.
Together, we're advancing agentic pentesting with more precise and controlled workflows for security teams.
https://t.co/0sFVq6hVd0
Strix just hit 10K Stars, in under 3 months✨
It’s been a crazy week seeing our metrics and usage almost double every day for both the hosted and the OSS versions.
Now ranked #1 trending repo this week and #3 for the month.
Let’s go 🚀